BTCPay Server Fixes critical LND credential vulnerabilities to prevent lightning wallets from being stolen
2026-08-12 00:45:29
According to CoinMeta, BTCPay Server has released version 2.4.2, which fixes a critical vulnerability that allowed unauthorized remote access to LND credential files. Attackers exploited this vulnerability to steal merchants' Lightning wallets. The project's release note describes a serious vulnerability involving macaroon files, which are used to manage access permissions for LND. BTCPay supporters also offer a recovery bonus equal to 10% of the returned funds, with a cap of 3 BTC. At current prices, the maximum reward is approximately $190,000. This incident is not a Bitcoin protocol vulnerability but rather a server-side security issue affecting certain servers that use LND and BTCPay Server settings. Affected merchants should update their systems as soon as possible to ensure security.
Source:Internet
This content is for market information only and does not constitute investment advice.
Follow HKWDB official accounts to stay updated
Hot Articles
Refresh

Web3: Circle obtains New York trust license, expanding USDC custody business.
07-31 22:04

Tesla reportedly plans to divest its China business to pave the way for integration with SpaceX.
07-31 21:54

web3: Foreign media: RWA perpetual contracts may expand faster than tokenization
07-31 21:24

Web3: Foreign media: Analysts say the real catalyst for XRP is not the Clarity Act.
07-31 20:55

Foreign media: Trump's children's accounts are unlikely to replace comprehensive family financial planning
07-31 20:24

