BTCPay Just Silently Locked Remote Lightning Access, Your Node May Already Be Compromised
Attackers have already drained Lightning nodes operated by Foundation and Citadel21, and BTCPay Server quietly restricted remote Lightning access before most operators even knew there was a threat.
The vulnerability targeted BTCPay's remote Lightning node connectivity, the feature that lets operators manage nodes without being physically present. What makes this particularly alarming is what nobody knows yet: the total amount stolen and the full number of affected operators remain unconfirmed. This is an open wound, not a post-mortem.
What Actually Happened
BTCPay Server is the backbone for thousands of Bitcoin merchants and self-sovereign payment operators globally. When Foundation, the hardware wallet company behind Passport, and Citadel21, a long-running Bitcoin media and merchant platform, both report drained nodes, this is not a niche edge case. These are credible, technically sophisticated operators.
BTCPay's response was to restrict remote Lightning access across the board, essentially pulling the emergency brake. That decision protects future users but does nothing for anyone already hit. The attacker or attackers accessed connected Lightning nodes through a vector in remote management, siphoning funds before operators could react.
Lightning Network funds move instantly and, by design, with minimal friction. There are no chargebacks, no rollbacks, no fraud departments to call. Once those channels are drained, recovery depends entirely on whether any funds can be traced or recovered through cooperative channel partners, which rarely happens cleanly.
Why This Is Bigger Than It Looks
The Lightning Network has been the centerpiece of Bitcoin's payments narrative for years. Every merchant integration, every conference demo, every "Bitcoin fixes this" argument about cross-border payments leans on Lightning working safely at scale. An unquantified theft from a tool as widely deployed as BTCPay Server introduces doubt at exactly the wrong moment.
BTCPay is open-source and self-hosted, meaning there is no central company sitting on a reserve to compensate victims. Operators absorb losses directly. For small merchants running nodes to accept Bitcoin payments, this could be devastating.
The restriction on remote access is a blunt but necessary fix. Expect a patched release with more surgical controls soon, but the timeline is not yet public.
What You Should Do Right Now
If you run a BTCPay Server instance with Lightning enabled, audit your node balances immediately and compare against your last known state. Disable remote Lightning access if you have not already. Check BTCPay's official GitHub and Telegram for patch announcements and do not re-enable remote access until a verified fix is deployed.
Watch this story closely. The moment a total stolen figure surfaces, market sentiment around Lightning-dependent projects will move fast.