btcpay and server issue an urgent security announcement: versions prior to 2.4.2 contain critical vulnerabilities
2026-08-09 14:53:32
According to CoinMeta, Wu said that btcpay and server issued an emergency security announcement stating that all versions prior to 2.4.2 (including the 2.4.2 candidate versions) contain a critical vulnerability. It has been confirmed that this vulnerability has been actually exploited by attackers, resulting in the theft of user funds. This vulnerability may allow unauthorized remote attackers to obtain the macaroon credential files of lnd (Lightning Network implementation), thereby controlling lnd nodes and transferring funds. The official team has confirmed that this vulnerability has been exploited and caused user funds to be stolen, and is urging users of lnd to immediately upgrade to btcpay 2.4.2 and lnd 0.21.1. btcpay server on-chain wallets are not affected, and the official team has not yet disclosed the specific amount of funds stolen.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.