Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

BTCPay Server: new vulnerability found in LNbank plugin

Newsroom by Newsroom
January 4, 2024
in Bitcoin
btcpay server
Share on FacebookShare on TwitterShare on Linkedin

The plugin that enables accepting Lightning payments without the need for one’s own node is being discontinued due to two vulnerabilities identified within a few days.

BTCPay Server, the open-source software enabling Bitcoin payments, allows the development and addition of advanced features through an external plugin system.

LNbank is an external plugin that enables an administrator of a BTCPay Server instance to become the custodian of funds for users of that instance, allowing them to receive and send Lightning transactions easily without the need for their own node.

Two bugs in two weeks

In just over two weeks, two severe vulnerabilities were found in LNbank, leading Dennis Reimann, the developer of the plugin, to halt the development of LNbank.

The first bug, allowing the withdrawal of liquidity from the Lightning node of a BTCPay Server instance administrator, resulted in the loss of funds for some users. One user lost 4 BTC.

On December 25th, the BTCPay Server team identified a second vulnerability in version 1.9.0 of the plugin.

🚨A critical security vulnerability has been found in LNbank, external plugin v1.9.0.

To mitigate, all users using this plugin are urged to update immediately.

LNbank plugin is also being phased out in 1.9.2.

More information: https://t.co/WtIhYeB2xg pic.twitter.com/4sWdlozDtA

— BTCPay Server (@BtcpayServer) December 26, 2023

To mitigate the issue, the BTCPay Server team urges all users employing the LNbank plugin to update immediately with the newly released version.

Version 1.9.2 addresses the vulnerability in question and completely disables the transaction sending functionality.

Despite the update, Dennis Reimann has stated that version 1.9.2 will be the last version of LNbank, advising all users of the plugin to gradually phase out its usage, especially on an instance allowing open registration.

The two vulnerabilities found impact only users utilizing the LNbank plugin. Users who have not enabled it are unaffected and do not need to take any specific actions.

Previous Post

Not just Bitcoin: Argentina will also consider transactions completed with food as valid

Next Post

What is the passphrase?

Latest News

CFTC: funzionari rimossi per aver ostacolato criptovalute vicine a Trump
Bitcoin

CFTC: officials removed for obstructing Trump-linked crypto firms

by Newsroom
May 25, 2026
0

A New York Times investigation reveals how the CFTC pushed out staff who raised concerns about Polymarket, Crypto.com, and Gemini...

Read moreDetails
FTX: lo studio legale Fenwick & West paga 54 milioni per accordo stragiudiziale
Bitcoin

FTX: law firm Fenwick & West pays $54 million settlement

by Newsroom
May 25, 2026
0

The law firm that advised FTX before its collapse will pay $54 million to former customers of the platform.

Read moreDetails
Swan Bitcoin: causa da quasi 1 miliardo di dollari per i trasferimenti pre-fallimento di Prime Trust
Bitcoin

Swan Bitcoin: nearly $1 billion lawsuit over pre-bankruptcy transfers from Prime Trust

by Newsroom
May 19, 2026
0

Prime Trust's post-bankruptcy trust accuses Swan Bitcoin of using privileged access to drain assets before the custodian's collapse.

Read moreDetails
Bernstein promuove i miner sull’AI: oltre 90 miliardi di dollari in gioco
Bitcoin

Bernstein promotes miners on AI: over $90 billion at stake

by Newsroom
May 19, 2026
0

The research firm assigns Outperform ratings to IREN, Riot, CleanSpark, and Core Scientific, betting on 3.7 gigawatts of AI-linked capacity.

Read moreDetails
Claude Mythos AI: exploit su Apple M5 sviluppato in meno di una settimana
Bitcoin

Claude Mythos AI: exploit on Apple M5 developed in less than a week

by Newsroom
May 15, 2026
0

Security startup Calif claims to have used a preview version of Claude Mythos to build a working exploit against Apple...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.