BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running LND software after attackers exploited a critical vulnerability to obtain credentials and move funds. The flaw allowed an unauthenticated remote attacker to obtain macaroon credential files used to control LND and potentially take control of affected nodes. Version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard installations. At least two operators, including hardware wallet company Foundation and Bitcoin publication Citadel21, publicly reported drained Lightning nodes, though the total amount stolen and the number of affected operators remain unknown. BTCPay plans to restore remote access once the issue is deemed safely resolved.
Source: Read the original article

