Loading market data...

BTCPay Tells Lightning Users to Patch LND Now or Pull Servers Offline

BTCPay Tells Lightning Users to Patch LND Now or Pull Servers Offline

BTCPay has issued an urgent security advisory for anyone running LND, the Lightning Network daemon. The company says attackers have stolen credentials that can control Lightning wallets and move funds, and it's telling users to update immediately or take their servers offline.

The stolen credentials

According to the advisory, the attackers now have credentials that grant control over Lightning wallets. That means they can potentially drain funds from any affected node. BTCPay didn't disclose how the credentials were obtained, how many users are impacted, or which versions of LND are vulnerable. What it did say is that the risk is serious enough to warrant an immediate response.

Update or disconnect

The guidance is direct: patch LND right away, or shut down your server. For operators who can't apply a fix immediately, taking the node offline is the safer choice. Leaving a compromised node running while credentials are in the hands of attackers is not a viable option.

BTCPay's advisory doesn't name a specific patched version or provide a timeline for when one might be available. It also doesn't offer a workaround. The instruction is simply to update or disconnect.

What's at stake

Lightning wallets hold real bitcoin. If an attacker has the credentials to control those wallets, they can move funds without the owner's permission. The threat is active, not theoretical, and the warning reflects that urgency.

How to respond

Anyone running LND should treat this as an emergency. The first move is to check for an updated version of LND and apply it as soon as possible. If no update is available, the node should be taken offline until one is released. BTCPay's advisory is the source of truth, so keep an eye on their official channels for any further instructions.

It's also worth considering whether other credentials on the same server are at risk. If the attackers got in through a broader breach, they may have access to more than just the Lightning wallet. But BTCPay didn't say anything about that, so we can't speculate. What we do know is that the wallet credentials are compromised, and that's enough to act.