BTCPay Shields Lightning Nodes from Bot Probes with Security Update, Urges Immediate Upgrade
September 13, 2026
BTCPay Server reports that automated bots are probing publicly exposed Lightning nodes for a restart-time vulnerability that could allow administrative access to LND, prompting urgent hardening.
Security notices warn that these probing bots aim to take control over LND instances by targeting exposed Lightning nodes via automated routines.
Version 2.4.4, rolled out on September 7, introduces unique random passwords for new LND wallets and rotates passwords on older installations to close the credential-exposure risk.
BTCPay disabled external access to LND in its standard Docker deployment and added hardening measures to reduce the window for password changes during restarts.
This probing activity follows an August vulnerability that allowed attackers to obtain LND macaroon files and drain merchant wallets, though on-chain wallets remained unaffected.
Administrators are urged to upgrade to version 2.4.4 and remove manually exposed LND routes; a September 11 route-control update adds a supported remote-access option while keeping LND and Core Lightning interfaces disabled by default.
Older BTCPay wallets with a shared default password faced increased risk, as attackers could trigger a password change and request an administrator macaroon during vulnerable restart windows.
BTCPay’s standard reverse proxy now blocks unauthenticated wallet setup and unlock attempts, closing the restart-time exposure via the public network, though risks remain for operators using custom configurations.
BTCPay continues to monitor threats with involvement from exchanges, blockchain analytics firms, and law enforcement.
Custom deployments remain a concern; operators should audit proxy rules and migrate remote connections behind BTCPay’s managed controls as automated bot probing persists.
Summary based on 2 sources
Get a daily email with more Crypto stories
Sources

CryptoSlate • Sep 13, 2026
Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys
KuCoin • Sep 13, 2026
Malicious Bots Target Exposed Bitcoin Payment Servers to Steal Admin Keys