pull down to refresh
I am more concerned about things like hsm_secret. If the attacker got code execution on the pre-2.4.2 host, they could steal the long term identities of nodes.
We need more details about what exactly an attacker can do. In the most critical case we will need to rotate ALL secrets, and burn down nodes.
reply
No evidence of an RCE from what I can tell, just whats set in BTCPay
I don't run BTCP, this is what I've gleaned from the patch commits, you should reach out to the BTP devs to ameliorate any other concerns.
Yes if you have hotwallet keys in BTCPay itself
Unix socket should be ok since there's no creds like you said, would apply more to CLN REST etc