Morning Edition · Sunday, August 9, 2026Published at 2:30 AM EDT · New York
Stolen macaroon files stay valid after the update, so operators who patch without regenerating credentials remain exposed, and the bug was found only after a wallet developer lost money and read his logs.

BTCPay Server, the self-hosted payment processor used by bitcoin merchants who do not want a third party holding their funds, confirmed an actively exploited vulnerability and released version 2.4.2. The flaw allowed an unauthenticated remote attacker to retrieve the macaroon files that authorise commands to Lightning Network Daemon (LND), the most widely deployed Lightning implementation. Possession of those files is equivalent to control of the node.
Attackers used that control to force channels closed and move funds out. Hardware wallet maker Foundation and the bitcoin publication Citadel21 both reported that their nodes were emptied. The attack vector was credential theft rather than a cryptographic break, which matters for the remediation: patching the server closes the path used to steal the files, but any macaroon already copied remains valid until the operator deletes and regenerates it. BTCPay told operators who cannot patch immediately to take their servers offline.
The discovery route is the part practitioners are discussing. BTCPay founder Nicolas Dorier said the bug surfaced because Craig Raw, the developer of Sparrow Wallet, lost funds and then analysed his server logs. It was not caught by an audit or by automated code review. That sits awkwardly beside the argument, common through 2026, that machine-assisted analysis is now closing the gap between attackers and defenders on open-source infrastructure.
For a payment stack marketed on the premise that merchants should not rely on a custodian, the incident points at a different dependency. Self-hosting removes the custodian and replaces it with the merchant's own server administration. Anyone running a web-facing node inherits the full burden of patch discipline, credential rotation and log review, and the incident catalogue maintained by Rekt News has filled through 2026 with losses that originated at that layer rather than inside a smart contract.
Start a discussion in Townsquare.
More from this edition
Custodial payment processors and hosted Lightning services, which gain a concrete argument that merchant self-hosting carries an operational cost most small merchants cannot absorb.
The exposure was narrower than a blanket warning implies, applying to deployments running Lightning Network Daemon with the Greenfield application programming interface enabled, and no party has yet published a count of affected instances or a total loss figure.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The loss channel here is operational, not monetary policy or market structure: merchants running their own Lightning nodes are the exposed party, and their working capital sits in hot channels that cannot be air-gapped because payments must clear instantly. Every incident of this type raises the practical cost of self-hosted bitcoin payments relative to a custodial processor, which pushes small merchants toward intermediaries and slowly concentrates Lightning liquidity in professional routing nodes. That is the opposite of what the payment layer was designed to produce.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Bitcointalk Dev & Technical · Rekt News
Comments
0No comments yet.