ComfyUI Instance Hacked for Crypto Mining via Public IP Exposure

slpreme · reddit · 2026-08-11

The author shared a real-world incident where their ComfyUI instance was compromised after being exposed to the internet without protection. Attackers scanned for open ports and exploited the ability to remotely install custom nodes to achieve remote code execution (RCE) and mine cryptocurrency.

They warned the community never to expose ComfyUI directly, even with the normal security policy enabled. Recommendations include using a reverse proxy with password authentication, wiping the affected machine, and revoking all associated API keys.

Original post →

More from Safety

Safety channel →