BTCPay warns bots are probing exposed Lightning nodes after August wallet theft

  • BTCPay Server warns that bots are probing publicly exposed LND nodes for administrative access.
  • Version 2.4.4, released Sept. 7, addresses the newly described attack path.
  • Attackers exploited versions before 2.4.2 on Aug. 7 to obtain macaroons and move funds.

BTCPay Server has warned that automated systems are probing exposed Lightning nodes for administrative control after a separate critical vulnerability was exploited in August to obtain credentials protecting LND nodes and drain merchant wallets. LND (Lightning Network Daemon) is a widely used implementation of Bitcoin’s Lightning Network, a system for faster off-chain payments. BTCPay disabled external LND access in its standard Docker deployment, but bots are now targeting servers where operators manually restored it by repeatedly calling an LND password-change endpoint. The latest method differs from the August exploit but could similarly give attackers credentials controlling a node. The exposure occurs briefly after an LND restart while the wallet remains locked, because the password-change method does not then require a macaroon (a credential authorizing administrative actions). Older wallets also used a shared default password, allowing a reachable attacker to replace it before BTCPay’s internal unlocker and request an administrator macaroon. BTCPay has not reported a successful takeover through the new probing or connected the activity to the August attackers. The project said attackers on Aug. 7 exploited versions before 2.4.2 to obtain LND macaroon files and move funds, while standard on-chain wallets were unaffected. BTCPay and supporters later offered a bounty of 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000, and involved exchanges, blockchain analytics firms and law enforcement. Version 2.4.4, released Sept. 7, gives new LND wallets unique random passwords, rotates credentials on older installations and strengthens the standard reverse proxy. A route-control change merged Sept. 11 supports remote access while leaving LND and Core Lightning interfaces disabled by default. Custom reverse proxies and other independently exposed deployments remain the immediate concern, and operators have been urged to install 2.4.4, remove exposed routes and audit their proxy rules.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.