BTCPay Server operators spent the past days patching after a critical vulnerability was actively exploited against certain Lightning deployments. Project communications urged immediate upgrade to version 2.4.2, with LND users also pointed to a matching LND update path so credentials could be regenerated. Supporters later floated recovery bounties denominated in bitcoin for help tracing and recovering stolen funds.

The important boundary is architectural. This is not a consensus failure in bitcoin. It is an application and node-operations failure in a widely used self-hosted payments stack. Merchants choose BTCPay precisely to avoid custodial processors. That independence only holds if operators treat update hygiene like production banking software.

Early incident notes centered on LND-linked credential exposure rather than a blanket drain of every on-chain hot wallet. That still leaves real losses for operators who lagged the patch, and it underlines a recurring Lightning lesson: channel software, macaroons, and deployment defaults are part of the security surface merchants often underestimate.

Watch disclosed loss totals, whether non-LND setups stay clean, and how quickly merchant hosts enforce minimum versions instead of leaving dashboards on update when convenient.