
Bots attack exposed BTCPay Server Lightning nodes
- —Bots call the LND password-change endpoint in the window after a restart while the wallet is locked
- —In August, an exploit in versions before 2.4.2 allowed theft of macaroon files and withdrawal of funds
- —A 10% bounty on stolen funds was offered, capped at 3 BTC (~$190,000)
- —Version 2.4.4, dated September 7, rotates passwords and blocks unauthenticated access
Why it matters: Operators with their own reverse proxy need to urgently update BTCPay to 2.4.4 and close public access to LND, or funds could be stolen.
Source: CryptoSlate