Skip to main content
Sign in

BTCPay Server — Lightning LND Macaroon Exploit (August 2026)

avoid.net/btcpay-server-lightning-lnd-macaroon-exploit-august-202662/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

In August 2026, a critical, actively exploited vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain LND macaroon credential files, granting full administrative access to victim Lightning nodes and enabling fund theft. BTCPay Server released emergency patch v2.4.2 on August 7, 2026 to close the exposure, though already-stolen macaroon files remained valid until operators manually revoked them at the node level. Confirmed victims include hardware wallet company Foundation and Bitcoin publication Citadel21, with total losses undisclosed.

Connected Entities

1 entities
Organizations
BTCPay Server — Lightning LND Macaroon Exploit (August 2026)
Relationships
    Have evidence about BTCPay Server — Lightning LND Macaroon Exploit (August 2026)?

    Timeline(6 events)

    2026-08-04

    TOTP two-factor authentication bypass in BTCPay Server Greenfield API reportedly fixed internally (later included in v2.4.2 changelog).

    GitHub Release v2.4.2 / CoinDesk reporting

    2026-08-07

    Bitcoin Red Team (Craig Raw, Rob Hamilton, Calle, Evan Kaloudis) responsibly disclosed the LND macaroon vulnerability to BTCPay Server.

    BTCPay Server on X

    2026-08-07

    BTCPay Server issued public emergency advisory disclosing active exploitation. Foundation and Citadel21 nodes had already been drained before the advisory was published. BTCPay Server v2.4.2 released as emergency patch.

    BTCPay Server Blog / CoinDesk

    2026-08-08

    Multiple major outlets (CoinDesk, CoinTelegraph, Blockonomi, CryptoTimes) published coverage of confirmed thefts from Foundation and Citadel21. Total loss amounts not disclosed by either victim.

    CoinDesk

    2026-08-08

    BTCPay Server confirmed stolen macaroon files remain valid after patching and emphasized mandatory three-step remediation beyond the software update.

    CoinTelegraph / TFTC

    2026-08-09

    Ongoing coverage; no CVE number assigned; technical details of exact exploit path still withheld by BTCPay Server.

    CoinTelegraph
    Provenance & Audit Trail
    11 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/9/2026, 11:04:26 PM
      hash: BDxFUiJTw6wCSqyqWVJqv4K1zH6fRgAKVqTKveLNsRLc

    11 of 15 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/9/2026, 11:04:17 PM

    last updated: 8/10/2026, 1:21:31 AM

    avoid.net — verified advice for a post-truth world