Key Takeaways
CryptoSlate reports that malicious bots are probing exposed Bitcoin payment servers for a restart-time weakness.

According to CryptoSlate, malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys. BTCPay Server stated that automated systems are targeting manually exposed Lightning nodes to exploit a restart-time weakness that could grant administrative control.
The activity follows an August exploit where attackers obtained credentials protecting LND nodes and drained merchant wallets. While BTCPay disabled external access to LND in standard deployments, bots are now targeting servers where operators manually restored access by calling an LND password-change endpoint.
The vulnerability occurs during a short interval after LND restarts while its wallet remains locked, during which the targeted password-change method does not require a macaroon credential. Older BTCPay LND wallets compounded risk by using a shared default password.
BTCPay released version 2.4.4 on September 7 to address the issue by giving new LND wallets unique random passwords and rotating older shared credentials. However, custom reverse proxies remain exposed until operators remove public LND routes and audit access. CryptoSlate reports that BTCPay has not linked the bots to the August thefts.
Source & Fact-Check Note
This report is synthesized from coverage by CryptoSlate. Information has been fact-checked and structured for market clarity by CoinQuickly’s research desk.
Read original article at CryptoSlate ↗

