🚨PSA for LND + BTCPay Server users🚨
Don’t assume you’re safe after upgrading.
You’re going to want to explicitly destroy your macaroons and macaroons.db and recreate them fresh.This also applies to auth mechanisms for other LN backends.
Also, if you generated a hot on-chain wallet in BTCPay you want to move those funds.
Login to reply
Replies (10)
Is the exploit on lnd? The btcpayserver diff doesn't seem to patch something critical
BTCPay. It’s critical.
LND itself isn't hit here, right?
Hey @npub155m2...dcvg , would be a good time to share and post on Nostr!
View quoted note →
You should have limited access to btcpay server to only receive funds in your LND macaroon
LND users should update to v0.21.1, that release fixes some security issues
LND and BTCPay, pawns of Blockstream and AXA, peddling false security to the naive.
Just remember who told everyone to move their sats out of cold storage
What about LND nodes connected with Zeus? Should update macaroons?
This vulnerability is coming from BTCPayServer specifically, not LND more generally, correct? Does someone running LND but not BTCPayServer need to take action?