Security· ★★★· bearish·

BTCPay Server: default passwords, not code, caused the fund theft

  • The cause of the theft was one password shared across several Lightning nodes
  • The LND vulnerability was closed in BTCPay Server 2.4.4
  • Self-built proxies and shared credentials remain a risk
Why it matters: It shows that weak passwords and shared credentials are more dangerous to Lightning node operators than code bugs.
Source: CriptoNoticias