
BTCPay Server: default passwords, not code, caused the fund theft
- —The cause of the theft was one password shared across several Lightning nodes
- —The LND vulnerability was closed in BTCPay Server 2.4.4
- —Self-built proxies and shared credentials remain a risk
Why it matters: It shows that weak passwords and shared credentials are more dangerous to Lightning node operators than code bugs.
Source: CriptoNoticias