Skip to main content
Sign in

BTCPay Server — LND Macaroon Credential Exploit (August 2026)

avoid.net/btcpay-server-lnd-macaroon-credential-exploit-august-202652/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

BTCPay Server is a widely used open-source, self-hosted Bitcoin payment processor created in 2017. On August 7, 2026, the project disclosed and patched a critical pre-authentication vulnerability (present in all versions before 2.4.2) that allowed remote attackers to steal LND macaroon credential files and drain connected merchant Lightning nodes. The vulnerability was actively exploited before the public disclosure, with confirmed victims including hardware wallet maker Foundation and Bitcoin publication Citadel21; the attacker remained unidentified as of mid-August 2026.

Connected Entities

1 entities
Organizations
BTCPay Server — LND Macaroon Credential Exploit (August 2026)
Relationships
    Have evidence about BTCPay Server — LND Macaroon Credential Exploit (August 2026)?

    Timeline(6 events)

    2017-08-01

    Nicolas Dorier publicly announced BTCPay Server, an open-source self-hosted Bitcoin payment processor, as an alternative to BitPay.

    Bitcoin Magazine

    2026-08-07

    BTCPay Server issued an emergency security advisory confirming active exploitation of a critical pre-authentication vulnerability affecting all versions before 2.4.2 that allowed remote attackers to steal LND macaroon credential files. Version 2.4.2 was released the same day.

    BTCPay Server Blog (official security advisory)

    2026-08-07

    Foundation (maker of Passport hardware wallets) reported its BTCPay-connected Lightning node was drained overnight; CEO Zach Herbert confirmed attackers closed payment channels and swept funds. Citadel21 also reported its Lightning node was swept.

    CoinDesk (August 8, 2026)

    2026-08-08

    CoinDesk reported on the incident, noting victims were compromised before BTCPay's public warning went live.

    CoinDesk

    2026-08-10

    BTCPay Server supporters publicly pledged a recovery bounty of 10% of any returned stolen funds, capped at 3 BTC (approximately $190,000), open to anyone including the attacker who provides information leading to fund recovery.

    The Block

    2026-08-11

    CoinDesk published a follow-up report on the $190,000 bounty offer. The attacker remained unidentified and no recovery had been announced.

    CoinDesk
    Provenance & Audit Trail
    14 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/22/2026, 11:03:57 PM
      hash: EStCvXJvTwH58keRvYnM5wghRya2poWSGmzpfnVujXw6

    14 of 15 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/22/2026, 11:03:49 PM

    last updated: 8/23/2026, 1:56:43 AM

    avoid.net — verified advice for a post-truth world