Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys

NewsSun, 13 Sep 2026 18:30:17 UTC2 hours ago
Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys

Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control.

The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND nodes and drain merchant wallets.

BTCPay subsequently disabled external access to LND, a widely used implementation of Bitcoin’s Lightning Network, in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.

Related Reading

Bitcoin Core Lightning Docker bug leaves node operators exposed despite showing updated version

The latest mechanism differs from the vulnerability exploited in August but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node.

BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked. During that period, the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.

… Continue reading the full article at the original source below.

Read from Source · cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related