Security· ★★★· bearish·

Bots attack exposed BTCPay Server Lightning nodes

  • Bots call the LND password-change endpoint in the window after a restart while the wallet is locked
  • In August, an exploit in versions before 2.4.2 allowed theft of macaroon files and withdrawal of funds
  • A 10% bounty on stolen funds was offered, capped at 3 BTC (~$190,000)
  • Version 2.4.4, dated September 7, rotates passwords and blocks unauthenticated access
Why it matters: Operators with their own reverse proxy need to urgently update BTCPay to 2.4.4 and close public access to LND, or funds could be stolen.
Source: CryptoSlate