Attackers exploited a critical flaw in BTCPay Server to steal funds from users running versions prior to 2.4.2. The self-hosted Bitcoin payment processor confirmed the attack and urgently released version 2.4.2 to patch the vulnerability. The issue allowed an unauthenticated remote attacker to obtain .macaroon credential files for LND, a common Lightning Network implementation. BTCPay Server has urged all operators to update their systems immediately.
Source: Read the original article

