A new exploit targeting Bitcoin's Lightning Network infrastructure has drained merchant payment nodes, prompting an urgent warning from BTCPay Server for users to update their software or disconnect immediately.

The attack represents the latest in a series of security incidents hitting Bitcoin infrastructure this year, highlighting the ongoing challenges of operating self-custodial payment systems at scale.

How the Attack Works

The exploit targets BTCPay Server installations running LND (Lightning Network Daemon), the most widely used Lightning implementation. Attackers found a way to steal the credentials that control Lightning wallets associated with BTCPay instances, giving them the ability to initiate fund transfers from compromised nodes.

Once an attacker gains access to the LND credentials, they can open channels, route payments, and move funds out of the Lightning wallet. Because Lightning payments are designed to be fast and irreversible, stolen funds can be moved across the network before the node operator realizes what has happened.

BTCPay Server, an open-source self-hosted cryptocurrency payment processor, is used by thousands of merchants worldwide to accept Bitcoin payments without relying on third-party processors. The vulnerability affects any BTCPay installation running an outdated version of LND.

Immediate Response

BTCPay's development team issued an emergency advisory telling users running LND to either update to the latest patched version immediately or shut down their Lightning services entirely. The advisory was circulated across social media, developer forums, and the project's official communication channels.

The speed of the response underscores the severity of the vulnerability. Unlike exchange hacks that make headlines with nine-figure losses, Lightning node exploits typically drain smaller amounts spread across many individual merchants — but the aggregate damage can be substantial.

A Pattern of Infrastructure Attacks

This is not an isolated incident. Bitcoin's infrastructure layer has faced a string of exploits in 2026, targeting everything from custodial platforms to Lightning implementations. The pattern reveals a fundamental tension in decentralized systems: the security of self-custody depends entirely on the technical competence of each individual operator.

For merchants and small businesses using BTCPay to accept Bitcoin payments, the burden of maintaining secure infrastructure is significant. Unlike managed payment processors, self-hosted solutions require constant vigilance, prompt patching, and technical expertise that many users lack.

The Broader Implications

The exploit reignites the debate over the tradeoffs between self-custody and managed services in crypto. Proponents of self-custody argue that eliminating third-party risk is worth the additional responsibility. Critics counter that vulnerabilities like this one demonstrate why most users — and particularly merchants — are better served by regulated, insured intermediaries.

For the Lightning Network specifically, repeated security incidents threaten to undermine confidence in Bitcoin's layer-2 scaling solution. Lightning's growth depends on merchants being willing to run nodes and accept Lightning payments. Each high-profile exploit makes that proposition harder to justify.

What Users Should Do

BTCPay users running LND should update to the latest version immediately. Users who cannot update right away should take their Lightning servers offline to prevent potential exploitation. The BTCPay team has published detailed update instructions on their GitHub repository and official documentation.

Node operators should also review their recent transaction history for any unauthorized channel openings or payments. Any suspected compromise should be reported to the BTCPay team and law enforcement where applicable.

The vulnerability serves as a reminder that in self-custodial systems, security updates are not optional. They are the price of sovereignty.