Bots Target Lightning Nodes in Latest Security Threat
Bitcoin payment processor BTCPay Server has issued another warning about potential security threats to Lightning nodes. Following a critical vulnerability exploited by attackers in August, which allowed them to obtain credentials and drain merchant wallets, bots are now probing exposed nodes for administrative control.
The latest activity targets servers where operators manually restored external access to LND, a widely used implementation of Bitcoin's Lightning Network. During a brief window after LND restarts, while the wallet remains locked, the targeted password-change method does not require a macaroon, which is normally needed for administrative actions.
BTCPay has identified that older wallets using a shared default password increase the risk of an attacker submitting that password first and requesting administrator credentials. However, BTCPay has reported no successful takeovers through this new activity and has not linked it to the August attacks.