Brivv
BTCPay Server Users Race to Patch as Lightning Nodes Are Drained in Active Exploit
CryptoНовость5 мин чтенияИИ-ассистент

BTCPay Server Users Race to Patch as Lightning Nodes Are Drained in Active Exploit

BTCPay Server warned of an actively exploited critical vulnerability after attackers drained Lightning nodes belonging to users including hardware wallet maker

8 августа 2026 г.Источник: thedefiant.io

Attackers emptied Lightning nodes belonging to BTCPay Server users on Friday, including one run by hardware wallet maker Foundation, after the self-hosted bitcoin payment processor warned that a critical vulnerability was being actively exploited and told merchants to update to version 2.4.2 or shut their servers down.

Because BTCPay is self-hosted, there is no operator who can patch on behalf of its users. Every merchant, exchange and wallet running the software has to apply the fix on its own machine, and the thefts were already underway before the warning went out. The software sits behind bitcoin checkout for Namecheap, which ran $73 million in BTC revenue across 1.1 million transactions through BTCPay between May 2020 and October 2024, along with hundreds of smaller merchants and several wallet backends.

"There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds," the project wrote at 11:51 a.m. ET. "If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update." The post passed 550,000 views within five hours.

Founder Nicolas Dorier published release 2.4.2 the same morning with a one-line warning at the top: "This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can." The notes also tell integrators to upgrade NBXplorer, BTCPay's wallet-tracking backend, to version 2.6.10.

Zach Herbert, chief executive of Foundation, the company behind the Passport hardware wallet, said his node was gone before he read the alert. "How many BTCPay lightning nodes were swept? Our Foundation node was drained overnight by attackers," he wrote at 2:01 p.m. ET. He later narrowed the damage: "This was just our BTCPay server that we use for payment processing, the hot wallet was untouched – only the lightning node was drained. All channels were closed and funds were swept."

hodlonaut, the pseudonymous bitcoin commentator behind the zine Citadel21, reported the same pattern. "This is an ongoing attack on BTCPayserver users. Citadel21's lightning node was just swept," he wrote. "Fortunately there were not much funds there." At least one other operator described closed channels and drained funds in the replies to BTCPay's warning. Neither Herbert nor hodlonaut disclosed amounts, and no one has published a tally of how many nodes were hit or how much bitcoin moved.

How the Flaw Surfaced

The flaw surfaced because someone got robbed. Dorier credited Craig Raw, the developer of Sparrow Wallet, for working out what was happening. "We got extremely lucky that a dev was impacted who could analyze the logs to understand what was going on," Dorier wrote. "Somehow, this wasn't found AI scans, but by him losing money. :("

That cuts against the premise of the Bitcoin Red Team, the volunteer group that has spent this week running AI-assisted audits across bitcoin's open-source stack and that BTCPay thanked for the disclosure. Dorier said the group's scans missed it. "The AI report we got from red team didn't include this one," he wrote. "But this bug was really sneaky, I am not surprised a simple scan didn't find it, or thought it was low risk."

BTCPay has not said which flaw is being exploited, and Dorier ruled out the one authentication bug the changelog does disclose. After a user posted a Grok-generated explanation pinning the attack on that bug, Dorier replied: "This bug was found by the Red team, this isn't the critical bug in question."

The disclosed bug is a two-factor authentication bypass in Greenfield, BTCPay's API, fixed on Aug. 4. The handler checked only for FIDO2 hardware keys before enforcing a second factor, so accounts protected by an authenticator app could be reached with an email and password alone and receive an unrestricted permission claim. The browser login screen enforced 2FA correctly the whole time.

Source: The Defiant

Читайте Brivv в Telegram

Главные новости финтеха и крипто первыми — с кратким разбором, почему это важно.

Подписаться@brivv_com_ru

Похожие статьи

FinCEN раскрыла схемы pig butchering на $12,7 млрд и работу скам-центров в Азии
Крипто
Новость

FinCEN раскрыла схемы pig butchering на $12,7 млрд и работу скам-центров в Азии

FinCEN выявила криптомошенничества pig butchering на $12,7 млрд за два года, потери американцев в 2025 году достигли $7,2 млрд.

4 сентября 2026 г.2 мин чтения
21 банк и финтех-компания из стран G7 разрабатывают общий стейблкоин
Крипто
Новость

21 банк и финтех-компания из стран G7 разрабатывают общий стейблкоин

JPMorgan, HSBC, Standard Chartered и ещё 18 организаций из стран G7 создают общий долларовый стейблкоин, запуск запланирован на первую половину 2027 года.

2 сентября 2026 г.1 мин чтения
Блокчейн Fogo приостановил работу из-за кражи $3 млн в токенах FOGO
Крипто
Новость

Блокчейн Fogo приостановил работу из-за кражи $3 млн в токенах FOGO

Fogo Foundation столкнулась со взломом и кражей 400 млн FOGO на сумму около $3 млн, сеть остановлена для заморозки активов.

1 сентября 2026 г.1 мин чтения
Аналитики выявили вероятный rug pull токена GOLD на $312 тыс. в Solana
Крипто
Новость

Аналитики выявили вероятный rug pull токена GOLD на $312 тыс. в Solana

Lookonchain выявила вероятный rug pull токена GOLD в Solana: связанные с проектом кошельки заработали около $312 тыс.

1 сентября 2026 г.2 мин чтения