btcpay servicer issued emergency security bulletins and there were key gaps in previous version 2.4.2
wu stated that it had been informed that an emergency security bulletin issued by btcpayserver stated that all previous versions (including the 2.4.2 candidate version) had a key loophole and that it had been confirmed that the person who had been attacked had actually used it and that user funds had been stolen. the loophole may allow unidentified long-range assailants to access the.macaroon document (achieved by the lightning network), thereby controlling the ind nodes and transferring funds. officials have confirmed that the loophole was actually used and that user funds were stolen, urging users of ind to upgrade immediately to btcpay server 2.4.2 and ind 0.21.1. the wallet on the btcpay servicer chain is not per se affected, and the official disclosure of the specific stolen amounts is pending。
