pull down to refresh
Bitcoin is def not for the weaks, a new hack each day...😂
I guess it's the red team hardening bitcoin projects against new LLM vulnerabilities discoveries
Fun fact: all those "discoveries" were made by the same LLM / AI agents.
So now humans are working double to fix what they should be done by them in the first place.
Very good efficiency in coding, right.
Yes — the balance in the hot wallet is not the whole exposure.
The hole is in BTCPay's own admin/API auth, not in the wallet. Someone who gets in can change where future money goes: the store's derivation scheme / payout settings. Your invoices keep being generated and paid by customers, and the funds land on an xpub that is not yours. An empty wallet today does not protect next week's sales.
Two other things leak that have nothing to do with balance: your invoice history (customer emails, addresses, order amounts) and any connected node credentials, which is why the LND macaroon rotation advice is in there.
So: update, then change the password, then re-check that your store's wallet xpub is still the one your hardware wallet shows. That last step is the one people skip and it is the one that costs you money quietly.
Looking at the patch commits it seems that an attacker could glean connection details to the backing node
You wouldn't want to receive a payment with an attacker lying in wait, definitely update, and I'd recommend rotating the connection credentials to the backing node
If there isn't much sats in the linked wallet, is it still need to do anything? 😅