Home » BTCPay Offers Up to 3 BTC Bounty After Critical Exploit Drains Lightning Wallets

BTCPay Offers Up to 3 BTC Bounty After Critical Exploit Drains Lightning Wallets

by Terron Gold
0 comments

Supporters of BTCPay Server have committed to paying a recovery bounty worth 10% of any stolen Bitcoin recovered, capped at 3 BTC, following the critical vulnerability that allowed attackers to drain funds from merchant Lightning Network nodes. The bounty represents the latest response to an exploit that affected BTCPay installations running LND, where attackers obtained powerful administrator credentials known as macaroons and used them to access connected Lightning wallets and nodes. 

The bounty comes several days after BTCPay disclosed that the vulnerability was already being actively exploited and released emergency software version 2.4.2. While the patch closes the security flaw, the project has not publicly disclosed how much Bitcoin was stolen or how many nodes were compromised. Several users have independently confirmed that their Lightning nodes were drained. 

BTCPay Supporters Put Up 10% Recovery Bounty

The recovery effort offers anyone who helps retrieve stolen Bitcoin 10% of the amount successfully recovered.

If all of the stolen assets are returned, the bounty is capped at 3 BTC. At Bitcoin’s recent price, the maximum reward is worth roughly $190,000

The initiative is intended to encourage researchers, blockchain investigators, exchanges, and potentially individuals with information about the attacker to assist in tracing and recovering the stolen funds.

Attackers Obtained LND Admin Credentials

BTCPay has now provided additional information about how the vulnerability worked.

All BTCPay Server versions before 2.4.2, including release candidates for 2.4.2, contained a critical vulnerability that could allow attackers to obtain LND admin macaroon credentials.

A Lightning macaroon functions as an authorization credential for an LND node. An administrator-level macaroon can provide extensive control over the associated Lightning infrastructure.

Once attackers obtained those credentials, they could access connected LND wallets and nodes and ultimately move Bitcoin controlled by those systems. 

Regular On-Chain BTCPay Wallets Were Not Compromised

One important distinction is that the vulnerability did not compromise every BTCPay Server wallet.

BTCPay confirmed that its regular on-chain Bitcoin wallets, including hot wallets, were not affected by this specific vulnerability.

The primary risk involved users running LND-based Lightning infrastructure through vulnerable BTCPay installations. Users operating other Lightning implementations or not using Lightning were not exposed to this specific LND credential attack. 

BTCPay nevertheless strongly recommends that all operators update to the latest software.

Foundation and Citadel21 Confirm Their Nodes Were Drained

BTCPay has not disclosed the total number of victims, but several organizations have publicly confirmed losses.

Bitcoin hardware wallet company Foundation reported that its Lightning node was compromised, while Bitcoin publication Citadel21 also said its node had been drained.

Security researcher and Sparrow Wallet developer Craig Raw, who helped discover and privately report the vulnerability, revealed that he was also affected by the exploit. 

The incident demonstrates how quickly attackers were able to weaponize the vulnerability despite security researchers privately reporting it to BTCPay.

Researchers Receive Bitcoin for Finding the Bug

The BTCPay Server Foundation is separately rewarding the researchers responsible for discovering the vulnerability.

The foundation will donate 0.21 BTC each to Craig Raw and the Bitcoin Red Team fund for identifying and privately reporting the flaw. 

The Bitcoin Red Team is the volunteer security initiative using artificial intelligence and human researchers to aggressively examine Bitcoin-related open-source software for vulnerabilities.

Members include researchers such as Rob Hamilton, Calle, and Evan Kaloudis.

The group has quickly become an important part of Bitcoin’s security ecosystem as AI makes it possible to audit enormous amounts of open-source code significantly faster than traditional manual security reviews.

BTCPay Believes AI May Have Helped Find the Exploit

One of the most concerning developments surrounding the attack is the possibility that artificial intelligence helped attackers discover the vulnerability.

BTCPay warned that AI is changing the balance between cyberattackers and defenders because increasingly powerful models can cheaply analyze massive software repositories looking for exploitable weaknesses.

Bitcoin projects are particularly attractive targets because vulnerabilities can potentially provide direct access to valuable financial assets. 

BTCPay is now introducing stronger code-scanning and review processes with assistance from external organizations and says a more detailed postmortem of the incident is being prepared. 

Another Bitcoin Security Incident Follows COLDCARD

The BTCPay attack comes immediately after the massive COLDCARD hardware wallet vulnerability that has shaken the Bitcoin ecosystem.

Confirmed losses connected to the COLDCARD incident have now reached at least $116 million, according to reporting cited by The Block. Coinkite, the company behind COLDCARD, has said it believes someone likely used AI to examine older publicly available firmware and discover the long-hidden weakness. 

The two incidents involve completely separate vulnerabilities, but together they demonstrate how AI-assisted security research is rapidly changing the threat environment surrounding Bitcoin.

AI Is Accelerating Crypto Vulnerability Discovery

The problem extends beyond Bitcoin.

According to Chainalysis estimates cited by The Block, attackers stole approximately $36.7 million from unverified closed-source smart contracts during the first six months of 2026 by decompiling their bytecode, activity that researchers believe likely involved artificial intelligence. 

AI models can increasingly inspect software, analyze unfamiliar codebases, identify potential attack paths, and help researchers understand vulnerabilities that could previously require weeks or months of manual investigation.

That capability is available to both security researchers and malicious hackers.

What This Means for Crypto

The BTCPay recovery bounty demonstrates how the Bitcoin community is responding to a rapidly changing cybersecurity environment. Open-source development has traditionally relied heavily on developers and independent security researchers manually reviewing publicly available code. AI dramatically increases the amount of software that can be inspected, potentially allowing defenders to uncover vulnerabilities that have remained hidden for years.

But that advantage works both ways. Attackers can deploy the same AI models against public repositories and potentially discover exploitable vulnerabilities before developers do. The recent BTCPay and COLDCARD incidents show why the time between vulnerability discovery, responsible disclosure, patching, and exploitation may continue shrinking.

You may also like

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?

This website uses cookies to improve your experience. To read more or opt here visit the privacy policy. Accept Read More