Bitcoin infrastructure exploit drains merchant Lightning nodes

Share

A critical vulnerability in BTCPay Server allowed attackers to drain funds from connected Lightning nodes. The issue stemmed from Lightning credentials called macaroons that persisted after software updates and remained valid without manual revocation. Foundation, a hardware wallet maker, and Citadel21, a Bitcoin publication run by hodlonaut, are among the confirmed victims whose Lightning channels were emptied. BTCPay Server released versions 2.4.2 and 2.6.10 on August 7 and ordered operators to update immediately or shut down their servers. Associated hot wallets were not affected, as the flaw was specific to Lightning node authentication handling.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles