pull down to refresh

The reality is even if the vulnerability was disclosed responsibly and a fix was in place for some versions already, you very likely would not have it installed when you were hacked.
This is highly speculative.
One thing is to update to the newest shining version. Another is to do that after a critical security flaw has been found.
How many security vulnerabilities have been found on btcpayserver/lnbank on these three months?
The story that you noticed it after you woke up does not quite match to the transaction table nginx logs you provided.
Everything can be explained if he woke up afternoon. He didn't say he woke up in the morning.
in your nginx log there is lnbank call even on Dec 7
Maybe some testing during the investigation period?
But anyway it's good that you took the time to double check everything that has been said. We indeed should not blindly trust random people on Internet.
I know Hugo personally and he's pretty much a night owl and goes to bed at the very early hours of the morning, so the waking up in the afternoon part is totally normal for him.
reply
Thanks for vouching for that. It's absolutely true!
reply