Attackers emptied Lightning nodes run by BTCPay Server users on Friday, including one operated by hardware wallet maker Foundation. The open-source payment processor responded with an urgent warning: a critical vulnerability is being actively exploited, and merchants must update to version 2.4.2 or shut down.
What the attack targeted
The thefts hit Lightning nodes belonging to BTCPay Server users, not the payment server itself. Lightning nodes handle off-chain bitcoin transactions, and a compromised node can lose funds directly. Foundation, a company known for its hardware wallets, confirmed its node was among those drained.
BTCPay Server did not disclose how many nodes were affected or the total amount stolen. But the company moved fast, issuing a security advisory that called the vulnerability critical and said it was already being used in the wild.
The urgent patch warning
In the advisory, BTCPay Server told merchants to either update to version 2.4.2 immediately or take their nodes offline until they could. The wording left little room for delay. The company didn't offer a workaround, just a clear choice: patch or stop.
That kind of blunt directive is rare for an open-source project, which suggests the exploit is both easy to pull off and severe in its impact. For merchants who rely on Lightning for payments, the update is not optional.
Foundation's node hit
Foundation, the maker of the Passport hardware wallet and other bitcoin products, runs its own Lightning node as part of its services. The company confirmed that attackers drained that node on Friday. It didn't say how much was lost, but the fact that a security-focused hardware wallet company got hit underscores how broad the attack was.
Foundation has not yet said whether it will reimburse affected users or how it plans to prevent a repeat. Its response so far has been limited to acknowledging the incident and pointing to BTCPay Server's patch.
What merchants should do now
Anyone running a BTCPay Server Lightning node should check their version number right away. If it's below 2.4.2, the node is exposed. The safest move is to update before processing any more transactions.
For those who can't update immediately, BTCPay Server's advice is blunt: shut the node down. Leaving it running while the exploit is active is a gamble with real money. The attack is already happening, and there's no sign it's slowing down.
The question now is how many other nodes were drained before the warning went out, and whether the attackers are still scanning for vulnerable systems. BTCPay Server hasn't said when the next patch might arrive, but 2.4.2 is the only known fix so far.




