pull down to refresh

Ive patched the main btcpayserver container to 2.4.2

Are you referring to the hot wallet mainnet keys?

Id like to know more about the actual exposure here -- CLN uses a unix socket for RPC. There are no creds between CLN and BTCPayServer. There is nothing to rotate there.

Yes if you have hotwallet keys in BTCPay itself

Unix socket should be ok since there's no creds like you said, would apply more to CLN REST etc

reply

I am more concerned about things like hsm_secret. If the attacker got code execution on the pre-2.4.2 host, they could steal the long term identities of nodes.

We need more details about what exactly an attacker can do. In the most critical case we will need to rotate ALL secrets, and burn down nodes.

reply

No evidence of an RCE from what I can tell, just whats set in BTCPay

I don't run BTCP, this is what I've gleaned from the patch commits, you should reach out to the BTP devs to ameliorate any other concerns.

reply

ok, I got it

reply