LIVE
RedotPay Says It Will Defend Itself Against Binance LawsuitPutin Signs Russia's First Comprehensive Crypto LawPutin Signs Russian Law Regulating Bitcoin and CryptoCircle Shares Fall After EPS Beat, Net Income Gain, Revenue MissJapan FSA to Launch Crypto and Stablecoin Division by August 7: ReportThree Missouri Men Face 20 Years in Bitcoin Home Invasion PlotColdcard Wallet Hack Losses Reportedly Exceed $100 MillionCFTC Crypto Derivatives in 2026: Futures, Perpetuals, Margin, and Market OversightHow the SEC Classifies Crypto Assets and Tokenized SecuritiesCrypto Regulator Responsibilities by Product in 2026RedotPay Says It Will Defend Itself Against Binance LawsuitPutin Signs Russia's First Comprehensive Crypto LawPutin Signs Russian Law Regulating Bitcoin and CryptoCircle Shares Fall After EPS Beat, Net Income Gain, Revenue MissJapan FSA to Launch Crypto and Stablecoin Division by August 7: ReportThree Missouri Men Face 20 Years in Bitcoin Home Invasion PlotColdcard Wallet Hack Losses Reportedly Exceed $100 MillionCFTC Crypto Derivatives in 2026: Futures, Perpetuals, Margin, and Market OversightHow the SEC Classifies Crypto Assets and Tokenized SecuritiesCrypto Regulator Responsibilities by Product in 2026
Homepage/Bitcoin News/Bitcoin Infrastructure Exploit Drains Merchant Lightning Nodes
BITCOIN NEWS

Bitcoin Infrastructure Exploit Drains Merchant Lightning Nodes

BY Felix van Dijk·3 MIN READ·AUGUST 8, 2026

BTCPay Server, the open-source Bitcoin payment processor, is urging node operators to update immediately or shut down after an actively exploited flaw allowed attackers to drain funds from merchant-operated Lightning nodes. The merchant Lightning node exploit targets self-hosted infrastructure that businesses run to accept Bitcoin payments, turning a payment tool into a point of loss.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
5External source domains cited in the article
3 minEstimated time to read the full report

What the exploit did to merchant Lightning nodes

The incident centers on Bitcoin payment infrastructure tied to the Lightning Network, the layer that lets merchants settle small Bitcoin payments quickly. BTCPay Server, which operators run themselves rather than through a third party, sits at the heart of the affected setups. For related coverage, see Figma Holds $91M in Bitcoin ETF Exposure, Not 938 BTC.

The maintainers told operators to update or shut their instances down over an actively exploited flaw, according to reporting from The Defiant. In this context, “draining” means an attacker moving Bitcoin out of a merchant’s connected hot wallet or Lightning node without authorization. For related coverage, see MARA Reports $611M Q2 2026 Net Loss After Bitcoin Holdings Drop.

The exposure is specific to merchant nodes because those wallets are kept online to process incoming payments. That always-on posture is what distinguishes this from the approval-based thefts seen elsewhere in crypto, such as the Ekubo exploit that drained $1.4M in wrapped Bitcoin. For related coverage, see Bitcoin Depot Files for Chapter 11 Bankruptcy, Plans Gradual Shutdown.

Why merchant-operated infrastructure was exposed

The flaw is an implementation issue in the BTCPay Server software, not a break in the Lightning protocol itself. That distinction matters: the vulnerability lives in the merchant-facing application layer, and details are laid out in the project’s 2.4.2 security advisory.

Merchant environments carry more risk than casual users because they run connected hot wallets and Lightning channels that must stay funded and reachable to accept payments. A casual user can keep coins in cold storage; a merchant node cannot.

The precise root cause and total losses remain developing. The research available here does not confirm a dollar figure or the number of affected merchants, so any wider scope should be treated with caution. The pattern of an exploit draining live balances echoes cross-chain incidents like the Verus-Ethereum exploit that drained $11.6 million.

What node operators should do next

The immediate guidance from the maintainers is binary: update to the patched release or take the instance offline until you can. Operators who cannot upgrade right away are advised to shut down rather than leave a vulnerable node exposed, per Crypto Briefing’s account of the disclosure.

The fix ships in the 2.4.2 release, and the version history is tracked in the project’s public changelog. After patching, operators should review recent channel activity and wallet movements for unauthorized transactions.

For merchants running Bitcoin payment rails at scale, the episode is a reminder that self-hosted infrastructure carries operational risk beyond price exposure, a theme also visible as firms like Bitcoin Depot navigate their own restructuring. Operators should watch for follow-up disclosures from the BTCPay Server team confirming the full scope and any additional mitigations.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: thedefiant.io
  • External Source - Referenced domain: blog.btcpayserver.org
  • External Source - Referenced domain: cryptobriefing.com
  • Byline - Reported by Felix van Dijk
  • Coverage Desk - Primary editorial category: Bitcoin News