Pinned
Our analysis confirms that the attacker used exposed LND .macaroon credentials to access funds. Only LND users are affected, but we recommend everyone update to BTCPay Server 2.4.2.
We found no evidence that on-chain or hot wallets created in BTCPay Server were affected.
Thank




