BTCPay Server warns bots are probing exposed Bitcoin Lightning nodes for admin takeover

3 min read
BTCPay Server warns bots are probing exposed Bitcoin Lightning nodes for admin takeover
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

BTCPay Server says automated bots are probing manually exposed Lightning nodes for a brief window after restart, when they could replace LND passwords and gain administrator control. The activity follows a separate flaw exploited in August that let attackers drain merchant wallets, and it targets only operators who reopened access BTCPay had already locked down.

Bots target a restart-time gap

BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control. The payment processor said the opening appears during a short interval after LND restarts, while its wallet remains locked, and during that window the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.

Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay's internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node. BTCPay has not reported a successful takeover through the newly observed activity and has not linked the bots to the attackers behind the August thefts.

A second scare in one month

The renewed probing follows a difficult stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw let unauthenticated attackers obtain LND macaroon files and use them to move funds, though BTCPay's standard on-chain wallets were unaffected. Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000, and enlisted exchanges, blockchain analytics firms, and law enforcement to trace the stolen funds.

BTCPay subsequently disabled external access to LND in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.

Patched version leaves custom setups exposed

Version 2.4.4, released Sept. 7, addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, and older installations using the shared credential are migrated and have their passwords rotated. BTCPay's standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening on its managed public network path.

Those controls, however, cannot secure infrastructure operators configure independently. Administrators who built their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay's protections. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default. BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes while automated systems continue searching for reachable nodes.

Source: CryptoSlate

Trading involves risk.

Most traded markets

BTC / USD
+0.18% 77,250.3
ETH / USD
-0.54% 2,505.40
BNB / USD
-0.65% 721.56
SOL / USD
-0.24% 100.99
UNI / USD
-1.36% 6.240
XRP / USD
-0.57% 1.3543
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.