#What Was the Recent Vulnerability in BTCPay Server?
BTCPay Server, an open-source Bitcoin payment processor, recently revealed a significant vulnerability that allowed unauthorized access to Lightning Network nodes. This flaw permitted attackers to gain remote control of these nodes and withdraw funds. The vulnerability specifically impacted BTCPay Server installations that were utilizing LND Lightning nodes. As a result, attackers began exploiting this weakness even before a fix was made available.
#How Did the Flaw Occur?
The issue arose from .macaroon credential files, which serve as the authentication keys for accessing LND Lightning nodes. In the affected BTCPay Server versions, these files were accessible without any authentication or special privileges. Consequently, an attacker with knowledge of the system could easily seize the macaroon files and take complete control of a victim's Lightning node, creating an opportunity to drain funds from payment channels.
While the flaw only affected the Lightning integration layer and did not compromise on-chain Bitcoin wallets, reports indicated that theft had already occurred before the patch was released. BTCPay Server chose not to disclose intricate technical details in their initial communications to prevent providing further guidance to attackers while users were updating their systems.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#Who Discovered the Vulnerability?
The responsible disclosure of this vulnerability came from Craig Raw, the developer behind Sparrow Wallet, and other members of the Bitcoin Red Team, including Rob Hamilton, Calle, and Evan Kaloudis. Their collaborative efforts in detecting, evaluating, and reporting the vulnerability confidentially allowed BTCPay Server the necessary time to develop a resolution. In recognition of their efforts, BTCPay Server donated 0.42 BTC to the researchers. Historically, the project has incentivized security researchers, previously rewarding a $5,000 bounty for another discovered vulnerability in 2022. They also launched a new bounty program aimed specifically at recovering stolen funds due to this breach.
#What Should Users Do in Response?
Users of BTCPay Server need to take immediate action by updating to version 2.4.2 and LND version 0.21.1. For those unable to perform the update promptly, it is advisable to take the servers offline temporarily to mitigate exposure risks. Furthermore, the project advised users operating LND nodes to scrutinize their activity logs for any signs of unauthorized access. If macaroon files were compromised prior to the patch, merely updating the software will not suffice to prevent further loss; rotating credentials and potentially closing and reopening payment channels with new keys will be necessary to secure the node.