Security· ★★★· bearish·

BTCPay Server releases 2.4.4 update after attacks on LND API

  • Attacks target the /lnd-rest/btc/v1/changepassword endpoint
  • 2.4.4 creates a unique password for each new LND wallet
  • A vulnerability in versions before 2.4.2 led to fund theft in August
  • No successful breaches or new thefts have been confirmed this time
Why it matters: Operators with a self-hosted, publicly exposed LND API need to urgently update to 2.4.4 and check their wallet passwords.
Source: TokenPost