{"id":76512,"date":"2026-08-07T20:11:09","date_gmt":"2026-08-07T20:11:09","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/bitcoin-lightning-nodes-hit-as-btcpay-signals-emergency-2-4-2-fix\/"},"modified":"2026-08-07T20:11:09","modified_gmt":"2026-08-07T20:11:09","slug":"bitcoin-lightning-nodes-hit-as-btcpay-signals-emergency-2-4-2-fix","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/bitcoin-lightning-nodes-hit-as-btcpay-signals-emergency-2-4-2-fix\/","title":{"rendered":"Bitcoin Lightning Nodes Hit as BTCPay Signals Emergency 2.4.2 Fix"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">BTCPay Server faced an active vulnerability exploit that allowed attackers to steal funds from users.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Developers urged users to update to version 2.4.2 or shut down servers to prevent further losses.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Following the Coldcard hack, multiple nodes were drained in what appears to be a targeted attack.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>BTCPay Server Recommends Upgrading After Critical Vulnerability<\/h2>\n<p>The Bitcoin ecosystem is facing yet another attack on a self-hosted infrastructure service <a href=\"https:\/\/news.bitcoin.com\/featured\/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk\/\">after the recent Coldcard exploit<\/a>, which left a balance of over 1,700 BTC stolen, according to Galaxy Research.<\/p>\n<p>BTCPay Server, an open-source, self-hosted cryptocurrency payment processor, has announced it is facing an ongoing attack by unknown threat actors affecting its codebase.<\/p>\n<p>On social media, the BTCPay Server team stressed that there was a <strong>\u201ccritical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.\u201d<\/strong><\/p>\n<p>The vulnerability was disclosed by the Bitcoin Red Team, <a href=\"https:\/\/news.bitcoin.com\/security\/bitcoin-red-team-audit-coldcard-vulnerabilities\/\">a voluntary security group that has already found thousands of vulnerabilities<\/a> across hundreds of open-source projects after the Coldcard hack.<\/p>\n<p><strong>\u201cPlease update your BTCPayServer to 2.4.2 by going to Admin Dashboard -&gt; Server -&gt; Maintenance -&gt; Update &amp; verify the 2.4.2 version string in the footer. If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update,\u201d<\/strong> <a href=\"https:\/\/x.com\/BtcpayServer\/status\/2085755643659522240?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">BTCPay Server recommended<\/a>.<\/p>\n<p>In addition, the project prompted users to refresh macaroons and macaroons.db, two core files of the server; refresh auth strings and move funds if they are stored on a hot wallet generated using BTCPay.<\/p>\n<p>While figures for this exploit have not been released, there are at least two known instances where funds were swept. Zack Herbert, co-founder and CEO of Foundation, builders of the Passport Prime device, <a href=\"https:\/\/x.com\/zherbert\/status\/2085788368365875378?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">reported that their node was drained overnight<\/a>.<\/p>\n<p>Hodlonaut also found that the Citadel 21 lightning node funds were drained, with the caveat that it was not holding many funds due to precautions regarding <a href=\"https:\/\/news.bitcoin.com\/featured\/bip-110-supporters-prepare-pow-switch-if-miners-refuse-soft-fork-plan\/\">the possible activation of BIP-110.<\/a><\/p>\n<p>He stressed that this attack seemed targeted, aiming at \u201cthe very heart\u201d of the bitcoin social layer. <strong>\u201cColdcard and BTCPayserver. These are enthusiast\/hardcore tools, used by the people who live and bleed Bitcoin. This does not feel like chance,\u201d<\/strong> he concluded.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/bitcoin-lightning-nodes-hit-as-btcpay-signals-emergency-2-4-2-fix\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways BTCPay Server faced an active vulnerability exploit that allowed attackers to steal funds from users. Developers urged users to update to version 2.4.2 or shut down servers to prevent further losses. Following the Coldcard hack, multiple nodes were drained in what appears to be a targeted [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":76513,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76512"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=76512"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76512\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/76513"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=76512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=76512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=76512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}