Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Malicious Bots Probe BTCPay Server Weakness That Could Grant Administrative Control

BTCPay Server has warned that automated systems are targeting exposed Lightning nodes to exploit a restart-time vulnerability that could enable attackers to obtain administrative credentials and control merchant wallets.
56 minutes ago 5 views
Malicious Bots Probe BTCPay Server Weakness That Could Grant Administrative Control

BTCPay Server has warned that bots are systematically probing exposed Lightning nodes for a vulnerability that could grant attackers administrative control over the payment processor's infrastructure.

The activity involves automated systems targeting servers where operators manually restored public access to LND, a widely used Lightning Network implementation. Attackers are repeatedly calling an LND password-change endpoint, seeking to exploit a timing weakness that appears during a short interval after LND restarts while its wallet remains locked.

How the Vulnerability Works

During the restart period, the targeted password-change method does not require a macaroon—the credential LND normally uses to authorize administrative actions. Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay's internal unlocker might submit that default password first, replace it, and request an administrator macaroon that gives control over the node.

If successful, attackers could replace LND passwords, obtain administrator macaroons, and potentially control merchant wallets. BTCPay has not reported a successful takeover through the newly observed activity.

Context of Earlier Breach

The renewed probing follows a separate critical BTCPay vulnerability that attackers exploited in August. That flaw allowed unauthenticated attackers to obtain LND macaroon files and use them to move funds. BTCPay subsequently disabled external access to LND in its standard Docker deployment but acknowledged that operators who manually restored that access remain vulnerable.

Remediation Steps

Version 2.4.4, released September 7, addresses the conditions behind the latest attack path. New LND wallets now receive unique random passwords, while older installations using the shared credential are migrated and have their passwords rotated.

BTCPay's standard reverse proxy now blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening through its managed public network path. However, these controls cannot secure infrastructure that operators configure independently.

BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. Operators using custom deployments must audit their proxy rules and migrate remote connections behind BTCPay's managed controls while the automated probing continues.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $77,385.10+0.29% EthereumETH $2,512.91-0.34% Tether USDUSDT $0.9998-0.02% BNBBNB $722.78-0.74% XRPXRP $1.36-0.33% USDCUSDC $1.000.00% SolanaSOL $101.29-0.34% TRONTRX $0.3417+0.52% HyperliquidHYPE $78.63-1.77% ZcashZEC $1,108.78-1.69%
Prices by Coinranking. Informational only.