MonitoringCryptoSecurity incidentFirst tracked 2026-09-13Last changed 2026-09-13
Current outcome
BTCPay Server warns that malicious bots are actively probing exposed Lightning nodes for a restart-time weakness that could grant administrative control and enable theft of merchant wallets, with version 2.4.4 patching the issue but custom reverse proxies remaining at risk.
Progress timeline
1 material updates- #01
Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys
BTCPay Server warns that malicious bots are actively probing exposed Lightning nodes for a restart-time weakness that could grant administrative control and enable theft of merchant wallets, with version 2.4.4 patching the issue but custom reverse proxies remaining at risk.
Source evidence: CryptoSlate