Bots Target Exposed Lightning Nodes for Administrative Control
BTCPay Server has warned that malicious bots are actively probing exposed Lightning nodes for a potential route to administrative control. The activity follows a separate critical BTCPay vulnerability exploited in August, where attackers obtained credentials protecting LND nodes and drained merchant wallets.
The latest mechanism differs from the previous vulnerability but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node. BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked.
BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. A route-control change merged September 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default.