ZEUS post-mortem: BTCPay vulnerability led to infrastructure attack, no customer funds lost

RSync25 · x · 2026-08-14

ZEUS published a post-mortem of a security incident on August 5th: attackers exploited a known BTCPay Server vulnerability to gain admin access to an LND node. Services were taken offline and restored in stages over a week. No customer funds were lost. Attackers closed some LSP channels, but channel closes settle balances on-chain as designed. Users are advised to update BTCPay Server to 2.4.2+.

Original post →

More from Safety

Safety channel →