Crypto NewsAug 8, 20263 min readBy Akita Inu

Bitcoin infrastructure exploit drains merchant Lightning nodes

The core issue was disclosed in a BTCPay Server security advisory tied to the release of version 2. 4.

Bitcoin infrastructure exploit drains merchant Lightning nodes

A security vulnerability in Bitcoin payment infrastructure has been linked to a merchant Lightning nodes exploit, with funds reportedly swept from commercial operators before some could act on the warning. The incident centers on self-hosted payment tooling rather than a flaw in Bitcoin’s base layer.

The core issue was disclosed in a BTCPay Server security advisory tied to the release of version 2.4.2, which addresses a critical vulnerability in the open-source payment processor. Reporting from The Defiant described Lightning nodes being drained while operators were still reading the disclosure.

How the exploit drained merchant Lightning nodes

A merchant Lightning node is the always-on software a business runs to accept Bitcoin payments over the Lightning Network, holding funds in open payment channels so customers can pay instantly at checkout. For related coverage, see MARA’s Bitcoin stash fell 34% to under 36,000 BTC in H1.

The exploit targeted the payment infrastructure layer connected to those nodes, not the Lightning protocol or Bitcoin’s consensus rules. The distinction matters: the reported losses stem from an application-level weakness that BTCPay Server has since patched, not a break in Bitcoin’s base-layer security. For related coverage, see Bitcoin ETF Inflows Hit $102M as Ethereum ETF Adds $50M.

The mechanics of exactly how funds were moved have not been fully detailed in the public advisory, and this article does not speculate beyond what the critical vulnerability update confirms. What is established is that the affected parties were commercial node operators, and that a fixed release was published.

Why merchants carried the risk

Merchants are structurally more exposed than casual self-custody users. To accept payments around the clock, they keep active channels funded with hot liquidity, meaning coins sit in software connected to the internet rather than in cold storage.

That always-on posture, combined with checkout integrations and automation, widens the operational attack surface. Each dependency, from the payment server to the node it controls, is another component that must be trusted and kept current.

The risk here concentrated on deployment choices rather than on Lightning’s design. This mirrors a recurring pattern in crypto, where infrastructure and bridging layers rather than base protocols become the point of failure, as seen when the Verus-Ethereum bridge was exploited and when THORChain halted its chain after an exploit.

What comes next for Bitcoin payment infrastructure

The immediate response for operators is to apply the 2.4.2 update and review access controls, channel management, and wallet segregation, in line with the advisory’s guidance.

A merchant-targeted exploit can dent confidence in Lightning-based commerce even when the underlying network is unaffected, so the more durable question is one of infrastructure trust rather than protocol integrity. That trust matters for adoption, given the same rails that businesses use to accept Bitcoin payments depend on operators keeping self-hosted software hardened.

The patched release is available now, and operators running earlier versions are the group most exposed until they upgrade.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Akita Inu

Author

Akita Inu

Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.