Key facts
- BTCPay Server supporters are offering 10% of recovered funds, capped at 3 BTC, for information leading to the return of stolen Bitcoin.
- The exploit allowed attackers to obtain LND admin macaroons, granting control over Lightning Network nodes.
- Users running affected software are urged to update to version 2.4.2 immediately or take servers offline.
- BTCPay Server Foundation made modest contributions to security researchers for responsible disclosure.
BTCPay Server supporters have announced a bounty of 10% of recovered funds, capped at 3 BTC (approximately $190,000), for information that leads to the return of Bitcoin stolen in a recent exploit. The offer extends to anyone providing details that could help recover the assets, including the attackers.
The vulnerability allowed malicious actors to obtain LND admin macaroons, which are credentials granting extensive control over a Lightning Network node. These credentials were then used to access connected wallets.
BTCPay Server first alerted users to the attacks on Friday, advising them to install version 2.4.2 of the software or disconnect their servers. The project has not yet disclosed the total amount of Bitcoin stolen, the number of affected users, or whether any funds have been recovered.
If multiple tips contribute to the recovery, the bounty will be distributed among them, considering each victim's losses and the usefulness of each tip. The BTCPay Server Foundation also contributed 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for their responsible disclosure of the vulnerability.
The company stated it is enhancing code review processes and prioritizing security patches over new features, citing AI's role in making it easier for attackers to find software vulnerabilities. BTCPay emphasized the need for better tools, thorough reviews, rapid security responses, and support for researchers.
