📈 Get daily crypto insights that make you smarter about your money

A Bitcoin Payment Server Flaw Just Drained Merchant Funds Overnight — and the Attackers Were Already Inside

When the team at Foundation, a Bitcoin hardware wallet company, woke up on Friday morning, their Lightning Network payment node was empty. Someone had stolen the credentials that controlled it overnight, closed all the payment channels, and walked away with the funds. They were not alone — and the attack was spreading.

By Marcus Johnson | August 10, 2026

The Hook

The attack targeted BTCPay Server, the open-source payment processor that thousands of merchants use to accept Bitcoin without paying fees to payment companies. It is the backbone of Bitcoin’s merchant ecosystem — the software that lets a coffee shop or an online store take Bitcoin payments directly, with no middleman.

Late Friday night, the BTCPay team posted an urgent alert on X: attackers were exploiting a critical vulnerability in the software that exposed credential files called macaroons — think of them as digital keys that give whoever holds them full control over a Lightning Network node. With those keys, an attacker could seize the node, close its payment channels, and sweep the funds to their own wallet.

BTCPay told anyone running LND — the most popular Lightning Network software — to update immediately to version 2.4.2 or shut down their server entirely. For merchants who rely on Lightning payments to run their businesses, it was the kind of choice nobody wants to face: go offline and lose sales, or stay online and risk losing everything.

On-Chain Evidence

The victims started speaking up within hours. Zach Herbert, the CEO of Foundation, confirmed that attackers had drained his company’s BTCPay Lightning node overnight. The channels were closed and the funds were gone. Foundation’s on-chain hot wallet — the regular Bitcoin wallet inside BTCPay — was untouched, but the Lightning funds were swept.

Citadel21, a popular Bitcoin publication run by the pseudonymous commentator known as hodlonaut, reported the same thing. Their Lightning node had been cleaned out, though they noted that little money was held there. The attack was not selective — it was opportunistic, hitting any exposed server the attackers could find.

BTCPay has not disclosed how many users were affected or how much Bitcoin was stolen. The project said its standard on-chain wallets were not impacted — only deployments using LND were vulnerable. But funds held inside LND’s own on-chain wallet were also at risk, because those funds sit under the control of the compromised Lightning node.

The Core Conflict

Here is the unsettling part: this vulnerability was already known. It had been reported to BTCPay by members of the Bitcoin Red Team — a volunteer group of developers who spent the past week running AI models against Bitcoin codebases and filing thousands of bug reports. The Red Team, which includes developers like Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis, had responsibly disclosed the flaw to BTCPay before publishing their findings.

But the Red Team’s philosophy is to publish fast. Their reasoning is simple and terrifying: if we found this bug using AI, someone else will too. And by the time BTCPay’s public warning went out, attackers were already exploiting the vulnerability against live servers.

This is the fundamental tension in modern cybersecurity, and Bitcoin is now ground zero. The same AI tools that help security researchers find and fix bugs also help attackers find and exploit them. The Red Team found thousands of vulnerabilities across 390 Bitcoin projects in a single day. They cannot un-publish their findings, and they should not — the information is already out there. But the gap between discovery and exploitation has shrunk to almost nothing.

Market Implications

For everyday Bitcoin users, the implications go beyond the specific BTCPay vulnerability. The Lightning Network — Bitcoin’s primary scaling solution for fast, cheap payments — relies on software like LND and BTCPay. If merchants cannot trust that software, they cannot accept Lightning payments. And if Lightning does not work, Bitcoin’s utility as a payment system takes a significant hit.

The timing is also significant. This exploit came during what Calle called an “extremely bad” week for Bitcoin security. The Red Team’s audit found 85 critical bugs and 635 high-severity issues across 390 projects. The Coldcard hardware wallet breach, which began in late July and saw attackers drain wallets whose seed phrases were generated by faulty firmware, was still fresh in the community’s mind. That bug had been dormant since 2021 — meaning it went undetected by human auditors for five years before AI tools found it in hours.

For investors, the takeaway is nuanced. Bitcoin the network — the blockchain itself — has never been compromised. The problems are in the infrastructure layer built on top of it: wallets, payment processors, Lightning nodes, and the software that connects them. This is an important distinction, but it is cold comfort for users whose funds were stolen because they trusted the wrong software.

The Verdict

BTCPay is working on a full postmortem, expected in the coming days, which should reveal how the vulnerability worked and potentially how much was stolen. In the meantime, anyone running BTCPay with LND should have already updated to version 2.4.2.

For the broader Bitcoin community, this episode is a wake-up call about the gap between human and AI security auditing. The Red Team proved that a small group of volunteers with AI tools can find in 24 hours what the industry missed in years. The attackers proved that the same tools can be weaponized immediately.

If you hold Bitcoin, the lessons are practical: keep your funds in cold storage when possible, use hardware wallets from manufacturers that have not been flagged by recent audits, and be extremely cautious about running Lightning nodes with significant balances until the current wave of vulnerability reports has been addressed. The era of trusting open-source Bitcoin software by default may be coming to an end — replaced by an era where every line of code is scrutinized by machines that never sleep.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

3 thoughts on “A Bitcoin Payment Server Flaw Just Drained Merchant Funds Overnight — and the Attackers Were Already Inside”

  1. macaroons being stored in plaintext on disk is wild. every LN security guide from like 2021 mentions this exact risk. how do people still get caught slipping

  2. Foundation losing their Lightning node funds is brutal. Makes you wonder how many other BTCPay merchants are sitting exposed right now and dont even know it

    1. macaroon_wheeze_

      ^ this is exactly why I moved my node to a dedicated box. shared hosting for Lightning is asking to get drained

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,091.00-1.7%ETH$1,874.69-2.5%SOL$75.87-1.8%BNB$601.66-1.1%XRP$1.02-2.1%ADA$0.1956-1.1%DOGE$0.0697-1.3%DOT$0.8040-0.8%AVAX$6.46-1.2%LINK$8.27-0.8%UNI$3.94-2.6%ATOM$1.42+2.2%LTC$45.26-2.4%ARB$0.0802+2.4%NEAR$1.62-0.4%FIL$0.6980-1.8%SUI$0.6893-2.0%BTC$64,091.00-1.7%ETH$1,874.69-2.5%SOL$75.87-1.8%BNB$601.66-1.1%XRP$1.02-2.1%ADA$0.1956-1.1%DOGE$0.0697-1.3%DOT$0.8040-0.8%AVAX$6.46-1.2%LINK$8.27-0.8%UNI$3.94-2.6%ATOM$1.42+2.2%LTC$45.26-2.4%ARB$0.0802+2.4%NEAR$1.62-0.4%FIL$0.6980-1.8%SUI$0.6893-2.0%
Scroll to Top