# ThunderHub login password cause node to be compromised

**URL:** <https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577>\
**Category:** Bitcoin and Lightning\
**Created:** [November 8, 2021, 11:58am UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577 "2021-11-08T11:58:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrkaqz](https://avatars.discourse-cdn.com/v4/letter/m/919ad9/32.png) [@mrkaqz](https://community.umbrel.com/u/mrkaqz)\
**Post date:** [November 8, 2021, 11:58am UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577/1 "2021-11-08T11:58:36Z")

</div>

Hi Guys,

I have not sure how my node is compromise. I see a transaction that send out my SAT to someone wallet both on-chain and LN.

So, I decided to take down my current node and do full reset and create new seed.  
But I want to look back what is going on and how it compromises.

One thing that I can think off is the ThunderHub is still under default password “moneyprintergobrrr” and I do port forwarding the port 3000 to via dynamic DNS service.

I trying to find the way to change the password of the ThunderHub but cannot find how to change it.

Can anyone help?

---

<div class="post-metadata">

**Author:** ![mentat](https://avatars.discourse-cdn.com/v4/letter/m/74df32/32.png) [@mentat](https://community.umbrel.com/u/mentat)\
**Post date:** [November 8, 2021, 3:15pm UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577/2 "2021-11-08T15:15:58Z")

</div>

You have to do it over ssh:

[https://lightning.codes/post/2021/06/18/setting-the-password-for-thunderhub-on-umbrel-eng/](https://lightning.codes/post/2021/06/18/setting-the-password-for-thunderhub-on-umbrel-eng/)

See also this thread: [Changing passwords](http://community.umbrel.com/t/changing-passwords/858)

But it seems pretty crazy to direct traffic straight to your Umbrel when you can use a Tor browser to do it securely.

---

<div class="post-metadata">

**Author:** ![DarthCoin](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/darthcoin/32/1628_2.png) [@DarthCoin](https://community.umbrel.com/u/DarthCoin)\
**Post date:** [November 9, 2021, 4:58pm UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577/3 "2021-11-09T16:58:38Z")

</div>

1. Did you ever read the [Guides section](http://community.umbrel.com/c/guides/14/l/top/all) of this forum?  
In there is a troubleshooting guide with a specific point how to change that password. But I strongly recommend NOT to do it, if you do not know what are you doing.

2. Your node was compromised, not because TH has hardcoded password, but because you were sloppy not keeping it safe, I mean your TH onion address.  
Posting your onion address of that TH in public site, you expose yourself.  
Each Umbrel has its own onion address FOR A REASON.

---

<div class="post-metadata">

**Author:** ![mrkaqz](https://avatars.discourse-cdn.com/v4/letter/m/919ad9/32.png) [@mrkaqz](https://community.umbrel.com/u/mrkaqz)\
**Post date:** [November 10, 2021, 5:12am UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577/5 "2021-11-10T05:12:43Z")

</div>

I did not know that I post my TH onion address elsewhere in the public site.  
I still cannot figure out how I get compromise. Let me know if you can think of.

I have change my password of the TH now but to be safe I will just wipe everything and starting my new node instead.

---

<div class="post-metadata">

**Author:** ![DarthCoin](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/darthcoin/32/1628_2.png) [@DarthCoin](https://community.umbrel.com/u/DarthCoin)\
**Post date:** [November 10, 2021, 9:09am UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577/6 "2021-11-10T09:09:58Z")

</div>

wiping the node and start over will not serve to anything, if you will compromise it again.  
Maybe your devices from where you access it are compromised and NOT the node itself.  
If you have a malware that keylog all you type, you are doomed, whatever you do, no matter how many times you re-install Umbrel.

---

<div class="post-metadata">

**Author:** ![Dav](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@Dav](https://community.umbrel.com/u/Dav)\
**Post date:** [November 11, 2021, 11:05pm UTC](https://community.umbrel.com/t/thunderhub-login-password-cause-node-to-be-compromised/4577/7 "2021-11-11T23:05:24Z")

</div>

I wouldn’t say he was sloppy, I would say it’s a bad idea for TH to not have an easy way to change the password and by accidentally releasing the TH’s tor address shouldn’t mean that your node is now compromised.

The easiest way for someone to accidentally release the tor address into the wild is to paste it into the address bar of a non-tor browser by accident then the search engine has it and anyone with your search history has it. Probably countless other people have it too.

I would recommend changing it through SSH
