Attackers are exploiting a critical BTCPay Server vulnerability to steal LND credentials and drain funds from Lightning nodes. Foundation and Citadel21 have reported affected nodes. BTCPay released 2.4.2 and is urging operators to update immediately or take vulnerable servers offline.