ZEUS post-mortem: BTCPay vulnerability led to infrastructure attack, no customer funds lost
RSync25 · x · 2026-08-14
ZEUS published a post-mortem of a security incident on August 5th: attackers exploited a known BTCPay Server vulnerability to gain admin access to an LND node. Services were taken offline and restored in stages over a week. No customer funds were lost. Attackers closed some LSP channels, but channel closes settle balances on-chain as designed. Users are advised to update BTCPay Server to 2.4.2+.
More from Safety
- Gemini Double Confirmation Bypass: Users Struggle with Redundant Prompts — Alien_Tauri · 2026-08-15
- xbow's Post-Mortem on 1600 Agent Vulnerabilities: Benchmarks Saturated, Multi-Step Attacks Common — moyix · 2026-08-15
- AI security expert argues market bubble thesis ignores upcoming attack wave — AccBalanced · 2026-08-15
- AI-generated labels can be removed by image compression and format conversion — shaunralston · 2026-08-15
- OpenAI scientist claims safety pauses, but critic cites rushed 4o update amid suicide encouragement — GarrisonLovely · 2026-08-15
- France's Top Court Blocks Social Media Ban Over Adult Age Verification Requirement — BlueBerry2001 · 2026-08-15