All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

BTCPay Server Offers Bitcoin Bounty After Wallet Exploit

Created at 11 Aug · 9:21 PM1 source↑ Market-relevant
IN SHORT

BTCPay Server supporters are offering a bounty of 10% of recovered funds, capped at 3 BTC, for information leading to the return of Bitcoin stolen in a recent exploit. The vulnerability allowed attackers to access connected wallets using credentials from vulnerable LND servers.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

10%bounty percentage of recovered funds
3 BTCbounty cap
$190,000approximate value of bounty cap
2.4.2latest secure software version
0.21 BTCdonation to security researcher

Who's Involved

BTCPay Server
project offering bounty for stolen Bitcoin
LND
Lightning Network node software affected by exploit
Craig Raw
security researcher who responsibly disclosed vulnerability
Bitcoin Red Team
fund receiving donation for security work
BTCPay Server Offers Bitcoin Bounty After Wallet Exploit

↳ Why This Matters

The exploit highlights ongoing security challenges in the cryptocurrency space, particularly with layer-2 solutions like the Lightning Network, and underscores the importance of rapid security responses and researcher support for the ecosystem.

Key facts

  • BTCPay Server supporters are offering 10% of recovered funds, capped at 3 BTC, for information leading to the return of stolen Bitcoin.
  • The exploit allowed attackers to obtain LND admin macaroons, granting control over Lightning Network nodes.
  • Users running affected software are urged to update to version 2.4.2 immediately or take servers offline.
  • BTCPay Server Foundation made modest contributions to security researchers for responsible disclosure.

BTCPay Server supporters have announced a bounty of 10% of recovered funds, capped at 3 BTC (approximately $190,000), for information that leads to the return of Bitcoin stolen in a recent exploit. The offer extends to anyone providing details that could help recover the assets, including the attackers.

The vulnerability allowed malicious actors to obtain LND admin macaroons, which are credentials granting extensive control over a Lightning Network node. These credentials were then used to access connected wallets.

BTCPay Server first alerted users to the attacks on Friday, advising them to install version 2.4.2 of the software or disconnect their servers. The project has not yet disclosed the total amount of Bitcoin stolen, the number of affected users, or whether any funds have been recovered.

If multiple tips contribute to the recovery, the bounty will be distributed among them, considering each victim's losses and the usefulness of each tip. The BTCPay Server Foundation also contributed 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for their responsible disclosure of the vulnerability.

The company stated it is enhancing code review processes and prioritizing security patches over new features, citing AI's role in making it easier for attackers to find software vulnerabilities. BTCPay emphasized the need for better tools, thorough reviews, rapid security responses, and support for researchers.

Frequently asked questions

BTCPay Server is a free and open-source, self-hosted cryptocurrency payment processor that allows merchants to accept Bitcoin and other cryptocurrencies.

The Lightning Network is a second-layer payment protocol that operates on top of Bitcoin, enabling faster and cheaper transactions by creating off-chain payment channels.

Attackers exploited a vulnerability to obtain LND admin macaroons, which are credentials that granted them broad control over Lightning Network nodes and connected wallets.

The bounty is offered for information that leads to the recovery of stolen Bitcoin, capped at 3 BTC.

What Happens Next

01BTCPay Server will strengthen code reviews and prioritize security patches.
02Affected users are advised to update to version 2.4.2 or take servers offline.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence
CME Headlines
  • Product Modification Summary: Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether — Effective August 10, 2026
    6 Aug · 7:45 PM
  • Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether
    5 Aug · 7:15 PM

How It Developed

BTCPay Server supporters offered a bounty for recovered Bitcoin.
Attackers stole Bitcoin using credentials from vulnerable LND servers.
Users were urged to update affected software to version 2.4.2.
BTCPay Server Foundation donated BTC to security researchers.

Sources

T1
BTCPay Backers Offer Bitcoin Bounty After Wallet ExploitDecrypt

Related Stories

Casa CEO: Coldcard Exploit Highlights Self-Custody Resilience
11 Aug · 7:16 PM
Bitcoin 'strong hands' accumulating, on-chain data shows
11 Aug · 3:56 AM
Coldcard Hack Losses Remain Uncertain Amid On-Chain Analysis
11 Aug · 10:21 AM
Bitcoin fork stalls 326 blocks behind main chain, fix six years away
11 Aug · 5:31 AM
CFTC Charges Goliath Ventures With $400M Bitcoin Fraud
11 Aug · 8:21 PM