BlockBeats report: On August 9, BTCPay Server issued an urgent security advisory stating that all versions prior to 2.4.2, including the 2.4.2 release candidate, contain a critical vulnerability that has been actively exploited by attackers, resulting in the theft of user funds. This vulnerability could allow unauthenticated remote attackers to obtain the .macaroon credential file of LND (Lightning Network implementation), thereby gaining control of the LND node and transferring funds.
The official team has confirmed that the vulnerability has been actively exploited, resulting in the theft of user funds, and urges all LND users to immediately upgrade to BTCPay Server 2.4.2 and LND 0.21.1. The BTCPay Server on-chain wallet itself is unaffected, and the exact amount stolen has not yet been disclosed.
Public information shows that BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor focused on providing fee-free, intermediary-free Bitcoin payment solutions for autonomous individuals and businesses. Core protocol contributors have estimated that there may be hundreds of thousands of active BTCPay Server instances worldwide. The main GitHub repository has been downloaded over one million times.

