
BTCPay Server has launched a comprehensive bounty program offering 10% of recovered stolen bitcoin, up to 3 BTC (worth approximately $190,000), to anyone with information leading to the return of funds stolen from merchants last week. According to the latest announcement, the bounty is open to anyone with useful information, including the attacker, with the project asking people to write to its security address and stating secure channels are available on request. If multiple reports lead to recovery, the bounty will be split with victims according to how much each lost and how useful the information proved. The project is also paying researchers who found the flaw, donating 0.21 BTC each to developer Craig Raw and to the Bitcoin Red Team fund for their responsible security disclosure of the critical vulnerability. As per BTCPay's latest statement, the bounty is part of its response to the critical security flaw that exposed LND administrator credentials on vulnerable installations.
BTCPay Server has confirmed that attackers successfully exploited a critical vulnerability to steal funds from Lightning nodes running LND, prompting urgent calls for immediate updates. According to the latest reports, the flaw allowed unauthenticated remote attackers to obtain ".macaroon" credential files** - files that give software permission to interact with LND Lightning nodes. BTCPay confirmed that attackers used these credentials to take control of affected nodes and drain their channels, though the project's standard on-chain wallets were not impacted. The project has instructed server administrators to immediately install version 2.4.2 through the Admin Dashboard, confirming the version number in the server footer reads 2.4.2 to ensure proper installation. While the team said funds may be at risk, it is unclear how many users have been exploited or how much has been lost, if any. The vulnerability affected all releases before version 2.4.2, including release candidate versions of 2.4.2, and allowed an attacker to obtain LND admin macaroon credentials from exposed BTCPay instances. A macaroon works as an authentication credential for a Lightning node, with an administrator macaroon providing extensive permissions over the associated wallet, making access to these credentials crucial for controlling funds held through affected LND setups.
Several high-profile victims have confirmed their Lightning nodes were successfully swept by the attackers. Hardware-wallet maker Foundation reported that attackers drained the company's BTCPay Lightning node overnight, closing its channels and sweeping the funds, while leaving its BTCPay on-chain hot wallet untouched. Citadel21, the bitcoin publication run by pseudonymous commentator hodlonaut, also reported that its Lightning node had been swept, though it said little money was held there. The vulnerability had already been reported to BTCPay by members of the Bitcoin Red Team - a group of developers that began pointing AI models at bitcoin codebases this week and has filed thousands of findings across hundreds of projects since. BTCPay credited Red Team members Craig Raw, Rob Hamilton, Calle and Evan Kaloudis with responsibly disclosing the issue and helping analyze it. Raw later said he had also been affected by the exploit, demonstrating the widespread nature of the vulnerability.
BTCPay has enlisted exchanges, blockchain analytics firms and law enforcement to help trace the stolen funds, while urging merchants to report losses and keep most holdings in cold storage. In a separate post, BTCPay said exchanges, blockchain analytics firms and law enforcement have offered help tracing the money, and urged affected merchants to report the theft to local police and to any service the funds are traced to. The project advised merchants to keep funds in cold storage and move excess out of hot wallets regularly, "especially during this period of rapid, AI-driven change." The Bitcoin Red Team is the volunteer effort that began pointing AI models at bitcoin codebases this month and has filed thousands of findings across hundreds of projects, including the report that led to this patch. The exposure applies specifically to deployments using LND, and funds held inside LND's own on-chain wallet can still be at risk because they sit under the compromised Lightning node. BTCPay is also introducing stronger code-scanning and review procedures with assistance from several external organizations, while preparing a full postmortem that is expected to provide comprehensive details about the attack methodology and mitigation strategies.
The BTCPay Server incident represents the fourth major Bitcoin/crypto custody security event this week, compounding risk-off sentiment for self-hosted infrastructure. According to live market data, BTC is trading at $64,564, down just 0.25% over 24 hours - the market has not yet priced in significant contagion. However, the event adds incremental bearish pressure to sentiment, particularly for the payment-infrastructure narrative surrounding Bitcoin. For Bitcoin-correlated equities including MicroStrategy, Marathon Digital Holdings, and Riot Platforms, the exploit is an indirect risk-off signal rather than a fundamental driver. The direct price impact on Bitcoin is likely modest and short-lived, but the event reinforces skepticism about self-hosted infrastructure maturity. The exploit is a credibility test for Bitcoin's merchant adoption layer, as BTCPay is foundational to the argument that Bitcoin as a geopolitical payment rail can function without centralized custodians. The incident follows another major security breach, with Galaxy Research confirming 1,719 Bitcoin (worth roughly $111 million) has been stolen from Coldcard users, with total expected losses exceeding $130 million once outstanding cases are verified. As per BTCPay's assessment, the distinction between affected and unaffected users is crucial, as the vulnerability was specific to LND credentials and did not expose users running other Lightning implementations or those without Lightning connections.