Citadel21, a Bitcoin publication operated by the pseudonymous commentator hodlonaut, reported that its Lightning node had been compromised, though it noted minimal funds were stored there.
The vulnerability had been previously disclosed to BTCPay by the Bitcoin Red Team—a group of developers who began using AI models to analyze Bitcoin codebases this week and have since submitted thousands of findings across numerous projects.
BTCPay acknowledged the responsible disclosure by Red Team members Craig Raw, Rob Hamilton, Calle, and Evan Kaloudis, who also assisted in analyzing the issue.
The Red Team explained they published findings promptly anticipating independent discovery by others, noting attackers were already exploiting the flaw on live servers by the time BTCPay’s public alert went out.
BTCPay subsequently clarified its standard on-chain wallets—including hot wallets generated within its platform—remain unaffected by the credential flaw.
The exposure specifically impacts LND-based deployments, with funds in LND’s integrated on-chain wallet remaining at risk as they rely on the compromised Lightning node’s security.
BTCPay has not yet released technical details, emphasizing operators need time to patch. A full postmortem analysis is expected in the coming days.


