A critical vulnerability in BTCPay's Lightning channel management allows attackers to manipulate transaction routing. Patched versions now implement strict validation to prevent channel state attacks.
Merchants using BTCPay with Lightning Network payments are at risk. Users on outdated versions should immediately upgrade. Self-hosted instances are vulnerable until patches are applied.
BTCPay released patched versions restricting Lightning channel access to authorized nodes only. Merchants must update their instances and verify Lightning connectivity after upgrade.
While this exploit targets BTCPay specifically, it highlights broader Lightning Network security challenges. Channel state validation across implementations remains an ongoing focus area.
Check your BTCPay version immediately. Upgrade to the latest patched release, restart services, and verify Lightning channels are functioning. Merchants should audit recent transactions for anomalies.
Read More →