Security· ★★★· bearish·

BTCPay Server 2.4.4 closes LND vulnerability, but custom proxies remain a risk

  • 2.4.4 blocks unauthenticated LND routes in the bundled reverse proxy
  • New LND wallets receive a random password instead of the shared default
  • Bots scan /lnd-rest/btc/v1/changepassword on servers with a manual proxy
  • In August 2026, a 2.4.2 vulnerability led to fund theft, with a bounty of up to 3 BTC
Why it matters: Owners of BTCPay Server with a custom proxy need not only to update but also to close external access to LND, otherwise the node's funds are at risk.
Source: CryptoTicker