Cut Through CryptoBetaSubscribe
Update 7 of 8
BTCPay Thefts Confirmed

BTCPay Thefts Confirmed

Verified · 10 Aug 2026BitcoinAug 9, 2026

BTCPay Server confirmed attackers stole funds from merchant Lightning nodes through the critical flaw patched Friday, with Foundation and Citadel21 among named victims, per multiple outlets. The exploit captured node credentials on servers running outdated versions rather than breaking any cryptography; operators were again urged to update, rotate credentials and move hot-wallet funds. Some coverage framed the incident as part of a broader wave of exploits hitting Bitcoin infrastructure projects.

BTCPay: the drain didn't touch the vault

The BTCPay attackers never broke Bitcoin's cryptography. They never got a seed phrase. They grabbed a permissions file — a .macaroon, the little token that tells a Lightning node "this person is allowed to move funds" — off servers running an old version of BTCPay, the free software small merchants use to accept Bitcoin payments.

They stole keys to the office; they didn't crack the safe.

Coldcard's seeds, BTCPay's node credentials — none of it was Bitcoin failing. Everything built around it is where the money keeps leaking. Attackers and defenders are focused on the plumbing around Bitcoin, so best to make sure your taps are tightened.

Related storylines

6 sources