BTCPay Server has patched a critical vulnerability in version 2.4.2. The flaw allowed attackers to remotely access LND Lightning node credentials, enabling fund theft from payment channels. Thefts were confirmed before the patch was released, though the total amount stolen remains undisclosed. The project donated 0.42 BTC to the security researchers who reported the issue, including Craig Raw of Sparrow Wallet and members of the Bitcoin Red Team. Users must immediately update to BTCPay Server v2.4.2 and LND v0.21.1.
Source: Read the original article

