- September 13, 2026
- Posted by: admin
- Category: BitCoin, Blockchain, Cryptocurrency, Investments
Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control.
The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND nodes and drain merchant wallets.
BTCPay subsequently disabled external access to LND, a widely used implementation of Bitcoin’s Lightning Network, in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.
The latest mechanism differs from the vulnerability exploited in August but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node.
BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked. During that period, the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.
Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay’s internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node.
BTCPay has not reported a successful takeover through the newly observed activity or linked the bots to the attackers behind the August thefts.
BTCPay hardens nodes after August theft
The renewed probing extends a difficult security stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw allowed unauthenticated attackers to obtain LND macaroon files and use them to move funds. BTCPay’s standard on-chain wallets were unaffected.
Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000. BTCPay also enlisted exchanges, blockchain analytics firms, and law enforcement in efforts to trace the stolen funds.
Version 2.4.4, released Sept. 7, now addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, while older installations using the shared credential are migrated and have their passwords rotated.

BTCPay’s standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening through its managed public network path.
Those controls cannot secure infrastructure operators configure independently. Administrators who created their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay’s protections.
BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default.
That leaves custom deployments as the immediate concern. Operators using them must audit their proxy rules and migrate remote connections behind BTCPay’s managed controls while automated systems continue searching for reachable nodes.
The post Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys appeared first on CryptoSlate.
