Thanks to the Bitcoin Red Team (follow @Rob1Ham@craigraw@callebtc@evankaloudis) for the responsible security disclosure and for providing details to address the vulnerability.
To stay safe, make sure that even after the update, you:
- Completely refresh macaroons and macaroons.db
- Completely refresh auth strings for other LN backends
- If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet
🚨PSA for LND + BTCPay Server users🚨
Don’t assume you’re safe after upgrading.
You’re going to want to explicitly destroy your macaroons and macaroons.db and recreate them fresh. This also applies to auth mechanisms for other LN backends.
Also, if you generated a hot on-chain wallet in BTCPay you want to move those funds.
I just sent an email to BULL's entire mailing list telling them to turn of their BTCPay server. I should have told them to upgrade. That is my bad. I did tell them to follow @BtcpayServer. I rushed to communicate and I did not want to waste time or take chances. Thank you @BtcpayServer for creating the patch.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
@alexbosworth I stole BTC once. My BTCPay instance was hit by the LNBank plugin exploit. Luckily my BOS TG bot was notifying me of all the transactions back and forth. I waited for a new inbound txn from the scammer and then shut it down, got to keep 40000 scammer sats!
I’m honest enough to admit this…
The only reason I ever bought coldcards was because I wanted to be part of the maxi cool kids club.
That is an incredibly cringe and stupid reason for using any security product.
Let alone a bitcoin wallet.