⚡ LIVE
BTC Loading...

Bitcoin’s exploit week worsens as BTCPay flaw drains Lightning nodes



Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been swept, though it said little money was held there.

The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team — a group of developers that began pointing AI models at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since.

Read More: Bitcoin developers flag 85 critical bugs in an “extremely bad” situation.

BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with responsibly disclosing the issue and helping analyze it.

The group’s stated reason for publishing findings quickly was that people outside it would arrive at the same bugs, and by the time BTCPay’s public warning went out, attackers were already exploiting this one against live servers.

Meanwhile, BTCPay narrowed the scope after its initial alert, saying its standard on-chain wallets, including hot wallets generated inside BTCPay, are not affected by the credential flaw.

The exposure applies specifically to deployments using LND, and funds held inside LND’s own on-chain wallet can still be at risk because they sit under the compromised Lightning node.

BTCPay has not yet published technical details of the vulnerability, saying operators need time to patch. A full postmortem is due in the coming days.



Source link

BTCLFGTEAM
@Bitcoinlfgo

Follow on X →
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always do your own research (DYOR) before making any investment decisions.

Leave a Reply

Your email address will not be published. Required fields are marked *