BTCPay Server says automated bots are probing manually exposed Lightning nodes for a brief window after restart, when they could replace LND passwords and gain administrator control. The activity follows a separate flaw exploited in August that let attackers drain merchant wallets, and it targets only operators who reopened access BTCPay had already locked down.
Bots target a restart-time gap
BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control. The payment processor said the opening appears during a short interval after LND restarts, while its wallet remains locked, and during that window the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.
Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay's internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node. BTCPay has not reported a successful takeover through the newly observed activity and has not linked the bots to the attackers behind the August thefts.
A second scare in one month
The renewed probing follows a difficult stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw let unauthenticated attackers obtain LND macaroon files and use them to move funds, though BTCPay's standard on-chain wallets were unaffected. Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000, and enlisted exchanges, blockchain analytics firms, and law enforcement to trace the stolen funds.
BTCPay subsequently disabled external access to LND in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.
Patched version leaves custom setups exposed
Version 2.4.4, released Sept. 7, addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, and older installations using the shared credential are migrated and have their passwords rotated. BTCPay's standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening on its managed public network path.
Those controls, however, cannot secure infrastructure operators configure independently. Administrators who built their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay's protections. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default. BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes while automated systems continue searching for reachable nodes.
Source: CryptoSlate
Trading involves risk.