BTCPay has instructed users running the Lightning Network Daemon (LND) to apply security updates immediately or disconnect their servers from the network following the discovery of an active exploit targeting Bitcoin payment infrastructure. According to CoinDesk, attackers have stolen credentials capable of controlling Lightning wallets and moving funds, marking the latest incident in a string of attacks draining merchant Lightning nodes. The vulnerability places active payment servers at risk of total fund loss if left unpatched, compelling operators to choose between downtime and potential theft.
The incident represents another breach in Bitcoin's underlying infrastructure, specifically targeting the Lightning Network layer used for faster, cheaper transactions. Security researchers and node operators are now racing to secure systems before attackers can leverage the stolen credentials to drain remaining balances. The exploit affects the specific implementation of LND used by BTCPay Server instances, which powers payment processing for numerous merchants accepting Bitcoin via Lightning channels. This marks the second major infrastructure exploit to hit the ecosystem recently, underscoring persistent vulnerabilities in payment server configurations.
Concurrently, users of cryptocurrency-linked payment cards face a separate fund security deadline as two major card providers ceased operations. CryptoSlate reported that August 7 marked the final day for spending on Cypher and Osmosis cards, after which cardholders lost the ability to transact using the physical or virtual cards. The shutdown requires users to complete withdrawals, rewards claims, and wallet-access procedures before a subsequent deadline to avoid losing access to unbacked wallet balances. The report indicates that while the spending functionality terminated on August 7, the wallet-access window remains open temporarily, giving users a limited timeframe to recover funds.
However, failure to complete the necessary withdrawal and backup steps before the later date could result in permanent loss of assets held in unbacked wallets associated with the card programs. The dual crises highlight the operational risks facing both decentralized payment infrastructure users and centralized card service customers, particularly regarding custody arrangements and service continuity.
The convergence of these security events has created an urgent environment where Bitcoin Lightning node operators must implement emergency patches or risk total fund drainage, while former card users must navigate withdrawal procedures to secure remaining balances before access windows close. Both scenarios emphasize the critical importance of maintaining current security patches and understanding custody arrangements, as unpatched nodes and unbacked custodial wallets face imminent threats of irrecoverable fund loss.