BTCPay Server disables remote Lightning access after node drainings

BTCPay Server is cutting off remote access to Lightning nodes after attackers successfully emptied multiple wallets. The breach first surfaced when Foundation and Citadel21 reported their nodes were drained by unauthorized actors. While the project's lead developers haven't disclosed the total bitcoin lost or how many operators were hit, they've already pushed an emergency update to block the vulnerability. It's a messy blow for the open-source payment processor. The team's immediate fix restricts external control features that previously allowed users to manage their funds from secondary devices. Security researchers are still digging through the logs to determine if this was a credential leak or a deeper flaw in the software's communication layer. For now, node runners are being urged to update their instances to version 1.13.1 immediately to prevent further outflows. Will this forced restriction drive users toward more custodial solutions, or is it just a temporary speed bump for self-sovereignty?
Read full story at Cointelegraph →