LIVE
SEC proposes Regulation Crypto Assets framework for token fundraisingSparrow Wallet Issues Update After AI Flags Recent FixesEvernorth Clears SEC S-4 Hurdle for Nasdaq XRP Treasury VehicleDTCC Lists 21Shares Polkadot Staking ETF Shares Under TDOT TickerSEC Charges 38 Entities Over False Filings Targeting Retail InvestorsBitGo Buys NYDIG Trading Unit to Expand Institutional Crypto ServicesIris Energy Q4 Revenue Miss Lands as AI Pivot AcceleratesRipple Launches Delta-One Unit for Institutional ClientsSportradar Expands Polymarket Deal to Cover 20+ Sports LeaguesCrypto traders brace for Fed Chair Kevin Warsh's Jackson Hole speechSEC proposes Regulation Crypto Assets framework for token fundraisingSparrow Wallet Issues Update After AI Flags Recent FixesEvernorth Clears SEC S-4 Hurdle for Nasdaq XRP Treasury VehicleDTCC Lists 21Shares Polkadot Staking ETF Shares Under TDOT TickerSEC Charges 38 Entities Over False Filings Targeting Retail InvestorsBitGo Buys NYDIG Trading Unit to Expand Institutional Crypto ServicesIris Energy Q4 Revenue Miss Lands as AI Pivot AcceleratesRipple Launches Delta-One Unit for Institutional ClientsSportradar Expands Polymarket Deal to Cover 20+ Sports LeaguesCrypto traders brace for Fed Chair Kevin Warsh's Jackson Hole speech
Homepage/Bitcoin News/Bitcoin Infrastructure Exploit Drains Merchant Lightning Nodes
BITCOIN NEWS

Bitcoin Infrastructure Exploit Drains Merchant Lightning Nodes

·3 MIN READ·
MakeThe CC Presspreferred onGoogle

BTCPay Server, the open-source Bitcoin payment processor, is urging node operators to update immediately or shut down after an actively exploited flaw allowed attackers to drain funds from merchant-operated Lightning nodes. The merchant Lightning node exploit targets self-hosted infrastructure that businesses run to accept Bitcoin payments, turning a payment tool into a point of loss.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
5External source domains cited in the article
3 minEstimated time to read the full report

What the exploit did to merchant Lightning nodes

The incident centers on Bitcoin payment infrastructure tied to the Lightning Network, the layer that lets merchants settle small Bitcoin payments quickly. BTCPay Server, which operators run themselves rather than through a third party, sits at the heart of the affected setups. For related coverage, see Figma Holds $91M in Bitcoin ETF Exposure, Not 938 BTC.

The maintainers told operators to update or shut their instances down over an actively exploited flaw, according to reporting from The Defiant. In this context, “draining” means an attacker moving Bitcoin out of a merchant’s connected hot wallet or Lightning node without authorization. For related coverage, see MARA Reports $611M Q2 2026 Net Loss After Bitcoin Holdings Drop.

The exposure is specific to merchant nodes because those wallets are kept online to process incoming payments. That always-on posture is what distinguishes this from the approval-based thefts seen elsewhere in crypto, such as the Ekubo exploit that drained $1.4M in wrapped Bitcoin. For related coverage, see Bitcoin Depot Files for Chapter 11 Bankruptcy, Plans Gradual Shutdown.

Why merchant-operated infrastructure was exposed

The flaw is an implementation issue in the BTCPay Server software, not a break in the Lightning protocol itself. That distinction matters: the vulnerability lives in the merchant-facing application layer, and details are laid out in the project’s 2.4.2 security advisory.

Merchant environments carry more risk than casual users because they run connected hot wallets and Lightning channels that must stay funded and reachable to accept payments. A casual user can keep coins in cold storage; a merchant node cannot.

The precise root cause and total losses remain developing. The research available here does not confirm a dollar figure or the number of affected merchants, so any wider scope should be treated with caution. The pattern of an exploit draining live balances echoes cross-chain incidents like the Verus-Ethereum exploit that drained $11.6 million.

What node operators should do next

The immediate guidance from the maintainers is binary: update to the patched release or take the instance offline until you can. Operators who cannot upgrade right away are advised to shut down rather than leave a vulnerable node exposed, per Crypto Briefing’s account of the disclosure.

The fix ships in the 2.4.2 release, and the version history is tracked in the project’s public changelog. After patching, operators should review recent channel activity and wallet movements for unauthorized transactions.

For merchants running Bitcoin payment rails at scale, the episode is a reminder that self-hosted infrastructure carries operational risk beyond price exposure, a theme also visible as firms like Bitcoin Depot navigate their own restructuring. Operators should watch for follow-up disclosures from the BTCPay Server team confirming the full scope and any additional mitigations.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: thedefiant.io
  • External Source - Referenced domain: blog.btcpayserver.org
  • External Source - Referenced domain: cryptobriefing.com
  • Byline - Reported by Felix van Dijk
  • Coverage Desk - Primary editorial category: Bitcoin News