Our analysis confirms that the attacker used exposed LND .macaroon credentials to access funds. Only LND users are affected, but we recommend everyone update to BTCPay Server 2.4.2.
We found no evidence that on-chain or hot wallets created in BTCPay Server were affected.
Thank you to everyone in the community who sounded the alarm, helped us spread this information quickly, and contacted merchants. Please continue reaching out to BTCPay Server operators you know and ask them to update.
I am deeply sorry to the users who suffered devastating losses. If you were affected or have more questions my DMs are open.