By Isaac • September 13, 2026 11:13 pm •
BTCPay Server has shipped another security-focused update after detecting automated probes against Bitcoin Lightning nodes whose operators manually reopened outside access.
The warning does not cover every BTCPay installation. The standard Docker deployment had already disabled public access to the Lightning APIs.
The immediate risk sits with custom setups that put LND back on the open internet.
According to BTCPay Server, bots have been repeatedly calling LND’s password-change endpoint. That method can be reached without an authorization macaroon while an LND wallet is still locked.
Older BTCPay-managed LND wallets also shared a default password. During the brief window after an LND restart and before BTCPay’s internal unlock process completes, an attacker who can reach that endpoint
Continue reading
Join the conversation!
Please share your thoughts about this article below. We value your opinions, and would love to see you add to the discussion!