BTCPay Server released version 2.4.2 to patch a critical vulnerability that allowed unauthenticated remote access to LND credential files, after attackers exploited the flaw to drain merchant Lightning wallets. The issue involved .macaroon files used by LND to manage access permissions, which can act like keys granting access to node functions. BTCPay supporters also backed a recovery bounty equal to 10% of returned funds, capped at 3 BTC, worth approximately $190,000 at current prices. This is not a Bitcoin protocol exploit or a native on-chain wallet failure, but a server-side security issue affecting certain BTCPay Server setups using LND.
Source: Read the original article

