
Lightning Nodes Drained in BTCPay Exploit; Patch Lag Exposed
Multiple Bitcoin Lightning Network nodes running BTCPay Server were compromised and funds withdrawn before the project issued a public security alert. The vulnerability differs from the issue listed in BTCPay's official changelog, raising questions about disclosure coordination.
Published by CoinArticle’s AI-assisted newsroom · written from 1 cited source. How we work
The Breach Timeline
Hardware wallet maker Foundation and the Bitcoin publication Citadel21 both reported their Lightning nodes were swept of funds, in some cases hours before BTCPay Server issued its public alert. The two organizations discovered unauthorized withdrawals only after the project's security notice went live, suggesting a lag between the time the vulnerability was exploited in the wild and when users were notified to patch.
Mismatch Between Exploit and Disclosed Flaw
BTCPay Server said in its alert that the vulnerability under active attack is not the flaw documented in the project's changelog. The discrepancy raises questions about whether the publicly disclosed issue is the same vector that drained user nodes, or whether multiple vulnerabilities were present. BTCPay did not immediately clarify whether the exploit in the wild exploits an undisclosed flaw or a known issue the project chose not to detail in its change log.
Implications for Node Operators
The incident underscores the risk faced by Lightning node runners using managed server software. Operators who did not patch immediately risked losing funds held in Lightning channels. BTCPay Server is widely used by merchants and custodians to accept Bitcoin payments; many run Lightning nodes alongside their payment infrastructure. The project has recommended all users apply the patch without delay.
Why It Matters
For Traders
Lightning node operators with open channels should verify their node status and patch immediately; any unpatched nodes remain at risk of fund loss.
For Investors
The incident exposes operational risk in Lightning infrastructure and may slow merchant adoption of Layer 2 payment solutions until confidence in server software security improves.
For Builders
Lightning application teams should audit their dependency on BTCPay Server internals and implement rate-limiting or multisig controls to mitigate single-vulnerability exposure.
This article is for information only and is not financial advice. Read the full disclaimer.






