Malicious Bots Target Exposed Lightning Nodes in Coordinated Attack
BTCPay Server has issued a warning that malicious bots are actively probing exposed Lightning nodes to steal administrative control. This activity follows a previous vulnerability in August where attackers exploited BTCPay's LND nodes and drained merchant wallets, resulting in the loss of approximately $190,000.
The latest mechanism differs from the previous exploit but could lead to similar consequences: an attacker obtaining credentials that can control an LND node. The bots are targeting servers where operators manually restored access to LND, repeatedly calling a password-change endpoint during a brief interval after LND restarts.
BTCPay has taken steps to harden its nodes, releasing version 2.4.4 on September 7. This update addresses the conditions behind the latest attack path by providing unique random passwords for new LND wallets and migrating older installations using shared credentials.