
BTCPay restricts remote Lightning access after attackers steal funds
BTCPay Server has temporarily restricted remote connections to Lightning Network nodes after attackers exploited a vulnerability to steal credentials and move funds, according to Cointelegraph. The breach involved the theft of "macaroon" credential files used to control LND software, which could allow attackers to take control of nodes and transfer funds, with at least two operators publicly reporting losses. The project has since upgraded to version 2.4.2, which automatically regenerates these credentials, and advised operators to check for unauthorized payments and discrepancies. It also noted that those exposing LND through additional routes outside BTCPay must rotate credentials separately, as the update does not close independent access routes.









