BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

BTCPay Warns Bots Probe Exposed LND Nodes for Admin Access

BTCPay Server has warned that automated bots are probing manually exposed LND nodes in an attempt to gain admin access, an activity the project says it observed on servers where operators re-

AnonymousCryptoCompass newsroom
September 13, 2026
4 min read
NEWS
BTCPay Warns Bots Probe Exposed LND Nodes for Admin Access
CryptoCompass editorial visual for bitcoin coverage.

BTCPay Server has warned that automated bots are probing manually exposed LND nodes in an attempt to gain admin access, an activity the project says it observed on servers where operators re-enabled external Lightning API access that its standard deployment disables. The warning describes attempted access, not a confirmed takeover.

What BTCPay's LND warning says about bot activity

The core of the BTCPay LND warning is straightforward: the project says it has seen bots targeting servers where operators manually re-enabled external LND API access after it was disabled in the standard Docker deployment, according to BTCPay Server. For related coverage, see Trezor: Shipping Breach Exposed 80,689 Customers’ Details.

Bots probing for admin access

The observed bots repeatedly call LND's password-change route, which does not require a macaroon while the wallet remains locked. Older BTCPay LND wallets used a shared default password, and BTCPay describes a brief interval after restart, before its internal unlocker reaches the wallet, when an attacker could potentially change that password and request an admin macaroon. For related coverage, see Cosmos Hub Resumes Blocks; Ledger ATOM Issues Persist.

BTCPay said it observed bots attempting to target servers where this access had been manually re-enabled. The activity is probing for admin access, and the project does not describe the bots as having obtained it. This mirrors concerns raised earlier this year when a Bitcoin infrastructure exploit drained merchant Lightning nodes. For related coverage, see Chainlink Whales Accumulate 10M LINK After 17% Correction.

The warning centers on manually exposed LND nodes

The scope qualifier matters. The warning targets nodes that operators manually exposed, not the standard configuration. BTCPay's standard Docker reverse proxy blocks unauthenticated LND wallet setup and unlock routes, which removes the restart window from the standard public network path.

Why the manually exposed qualifier matters

BTCPay tells operators not to expose the LND API manually through their own reverse proxy, and says those who already did should remove that access and update their server. Its new LND image creates each new wallet with a unique random password and automatically migrates existing wallets using the old default when they start.

The supplied context does not detail exactly how affected operators exposed their nodes beyond the manual reverse-proxy path BTCPay describes. The v2.4.4 release carrying these protections was published September 7. Operators weighing custom setups should also consider treasury hygiene: BTCPay's incident guidance recommends keeping funds in cold storage where possible and regularly sweeping excess hot-wallet balances, which limits funds at risk but does not itself patch exposure.

What remains unconfirmed about the probing attempts

BTCPay has not reported a successful takeover through the newly observed probing, nor linked those bots to earlier thefts, CryptoSlate reported. That is a limit of the reporting, not proof that no compromise occurred.

Access outcomes and impact remain unconfirmed

The available material establishes probing for admin access but no outcome. Successful access, financial losses, and the scale of the activity are not established. No probing logs, counts of exposed nodes, or attribution evidence were published in the warning.

A separate, earlier incident was confirmed: attackers obtained LND admin macaroon credentials and stole funds from some users, and updating to version 2.4.2 also regenerates the admin macaroon. That earlier theft, which prompted BTCPay to urge users to update, carries a recovery bounty of 10% of any recovered amount, capped at 3 BTC, though neither figure establishes the total stolen. The two events should not be conflated.

Bitcoin traded near $77,340 as the warning circulated, background context that does not measure any impact from the probing. Operators running custom LND exposure should watch for further BTCPay guidance on supported external-access controls in the days ahead.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read original article on coinlive.me