Subscribe Now
Trending News

Blog Post

THE BOTS KNOW YOUR LIGHTNING WALLET’S PASSWORD — AND THEY’RE KNOCKING ON YOUR SERVER RIGHT NOW
Featured

THE BOTS KNOW YOUR LIGHTNING WALLET’S PASSWORD — AND THEY’RE KNOCKING ON YOUR SERVER RIGHT NOW 

There is a window of a few seconds after your Lightning node restarts where your wallet has no real password at all. And right now, an automated army is scanning the internet to find that window and walk straight through it. BTCPay Server — the self-hosted Bitcoin payment processor running your shop, your donation page, your node — just admitted it.

The bots are already knocking.

Bots are hammering exposed Lightning nodes, repeatedly calling the LND password-change endpoint. They are targeting servers where operators manually re-exposed LND after BTCPay locked it down last month. The prize: a credential that gives administrative control of the node — and the wallet sitting behind it.

Here is the part that should make you angry.

For a short interval after LND restarts, the wallet is still locked — and during that window, the password-change call does not require a macaroon, the credential LND normally uses to authorize admin actions. Worse: older BTCPay LND wallets shipped with a shared default password. One password. For everyone. The bots memorized it. If a bot reaches the interface before BTCPay’s own internal unlocker, it submits that default password, replaces it, and mints itself an administrator macaroon. Full control of the node. Your node. Their wallet.

This is wave two of a war BTCPay already lost once.

In August, attackers exploited a critical flaw affecting every version before 2.4.2 — unauthenticated attackers grabbed LND macaroon files and drained merchant wallets in the wild. BTCPay yanked external LND access from its standard Docker deployment, slapped a bounty on the stolen funds (10% of recovered bitcoin, capped at 3 BTC, about $190,000 at the time), and dragged in exchanges, blockchain forensics firms, and law enforcement. The dust had barely settled. Now the bots are back with a new route.

The fix exists. It only works if YOU install it.

Version 2.4.4, released September 7, closes this path. New wallets get unique random passwords. Older installations get migrated and their passwords rotated. The standard reverse proxy blocks unauthenticated wallet setup and unlock methods. But here is the catch: none of this protects you if you built your own reverse proxy or manually exposed LND to the internet. The moment you step outside BTCPay’s managed door, you are a target — and nobody on earth is patching your server but you. BTCPay merged a route-control change on September 11 so you can keep remote access without exposing LND. You still have to install it. You still have to audit your proxy rules. You are the last line of defense, and the bots know it.

The uncomfortable truth about self-custody.

Holding your own keys does not end at safekeeping a seed phrase. It means running the software like someone is trying to break in — because someone is. Every second your node answers connections from strangers, it is being graded by machines that never sleep, never get tired, never hope. They have your default password. They have your restart window. What they do not have yet — is your installation. Keep it that way. Update to 2.4.4. Kill manually exposed LND. Audit the proxy today. Not this weekend. Today.

Stack your sats the way money was meant to be held — in your own hands. Get your hardware from Bull Bitcoin and use code LOVEISBITCOIN at https://loveisbitcoin.com/bull

How many of you are still running LND exposed to the open internet? Be honest — because the bots already know the answer.

Previous

THE BOTS KNOW YOUR LIGHTNING WALLET'S PASSWORD — AND THEY'RE KNOCKING ON YOUR SERVER RIGHT NOW

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal