Meta Force Space
BTC $77,255.00 +0.13% ETH $2,505.70 -0.60% SOL $101.00 -0.32% XRP $1.35 -0.65% BNB $721.13 -0.71% DOGE $0.0842 -0.80%
← Back to the news

Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys

Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control.

The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND nodes and drain merchant wallets.

BTCPay subsequently disabled external access to LND, a widely used implementation of Bitcoin’s Lightning Network, in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.

Related Reading

Bitcoin Core Lightning Docker bug leaves node operators exposed despite showing updated version

The latest mechanism differs from the vulnerability exploited in August but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node.

BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked. During that period, the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.

Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay’s internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node.

BTCPay has not reported a successful takeover through the newly observed activity or linked the bots to the attackers behind the August thefts.

BTCPay hardens nodes after August theft

The renewed probing extends a difficult security stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw allowed unauthenticated attackers to obtain LND macaroon files and use them to move funds. BTCPay’s standard on-chain wallets were unaffected.

Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000. BTCPay also enlisted exchanges, blockchain analytics firms, and law enforcement in efforts to trace the stolen funds.

Version 2.4.4, released Sept. 7, now addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, while older installations using the shared credential are migrated and have their passwords rotated.

Diagram showing the manually exposed LND restart window and the password and proxy protections in BTCPay Server 2.4.4.

BTCPay’s standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening through its managed public network path.

Those controls cannot secure infrastructure operators configure independently. Administrators who created their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay’s protections.

BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default.

That leaves custom deployments as the immediate concern. Operators using them must audit their proxy rules and migrate remote connections behind BTCPay’s managed controls while automated systems continue searching for reachable nodes.

Originally published by CryptoSlate on

Read the original on CryptoSlate ↗

Text and images are the property of CryptoSlate and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news