BTCPay Offers 3 BTC Bounty After Exploit Drains Lightning Wallets
- BTCPay Server is offering a 3 BTC bounty for information leading to the recovery of stolen funds after a critical vulnerability was exploited.
- Operators are urged to update to BTCPay version 2.4.2 immediately to mitigate the vulnerability affecting Lightning wallets.
- Security measures will be prioritized by BTCPay, focusing on patches and external code reviews to prevent future exploits.
BTCPay Server supporters have offered a recovery bounty of up to 3 BTC after attackers exploited a critical vulnerability to obtain credentials controlling some users’ Lightning wallets.
The bounty equals 10% of any stolen funds recovered, capped at 3 BTC if the full amount is returned. BTCPay said the offer is open to anyone providing actionable information, including the attacker, and that multiple contributors could share the payment based on their role in recovering funds.
We’re donating 0.21 BTC to @craigraw and 0.21 BTC to the Bitcoin Red Team for their responsible security disclosure of the recent critical vulnerability.
In addition, friends and supporters of the BTCPay Server project have committed to funding a bounty to recover the stolen… pic.twitter.com/qhs8zwoCvM
— BTCPay Server (@BtcpayServer) August 10, 2026
The flaw exposed LND admin macaroon credentials, which function as authorization tokens for Lightning nodes. Attackers who obtained them could access connected LND wallets and move funds. BTCPay said its standard on-chain Bitcoin wallets were not affected.
BTCPay released version 2.4.2 on August 7 with a fix for the actively exploited vulnerability and urged operators to update immediately. The current remediation also updates LND and regenerates its admin macaroon, according to the project’s incident response.
Hardware-wallet maker Foundation and Bitcoin publication Citadel21 were among users that publicly reported having Lightning nodes swept during the attack. The compromised funds were held in payment-processing Lightning infrastructure rather than Foundation’s main hot wallet.
BTCPay shifts resources toward security
The BTCPay Server Foundation will also donate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund for responsible vulnerability disclosure. Exchanges, blockchain analytics firms and law-enforcement agencies are assisting efforts to trace or freeze stolen funds.
BTCPay said it will prioritize security patches and hardening over major new features while expanding external code review and scanning. Its warning that automated tools are making large codebases cheaper to probe follows similar concerns raised during the recent Boltz shutdown, although neither incident establishes that AI was responsible for discovering this particular flaw.
Affected operators have been asked to provide on-chain addresses and transaction details as recovery efforts continue.
