Crypto World
BTCPay Server supporters back 10% bounty to recover stolen Bitcoin
BTCPay Server supporters have backed a recovery bounty equal to 10% of funds retrieved from a recent Lightning wallet exploit, with the reward capped at 3 BTC if all stolen assets are recovered.
Summary
- BTCPay Server supporters have backed a 10% recovery bounty, capped at 3 BTC if all stolen funds are recovered.
- The exploit exposed LND admin macaroon credentials, allowing attackers to access connected Lightning wallets.
- BTCPay fixed the vulnerability in version 2.4.2, while its onchain wallets were not affected.
- The BTCPay Server Foundation is donating 0.21 BTC each to Craig Raw and the Bitcoin Red Team fund for discovering and reporting the flaw.
- BTCPay said AI may have helped uncover the vulnerability and is preparing a detailed postmortem.
The BTCPay Server project said on Monday that the bounty is part of its response to a critical security flaw that exposed LND administrator credentials on vulnerable installations, days after users were told to immediately upgrade to version 2.4.2.
The open-source Bitcoin payment processor has not disclosed how much cryptocurrency was stolen or how many servers were compromised. However, several affected users, including Foundation and Citadel21, have reported that funds held in their Lightning nodes were drained.
BTCPay said the vulnerability affected all releases before version 2.4.2, including release candidate versions of 2.4.2. The flaw allowed an attacker to obtain LND admin macaroon credentials from exposed BTCPay instances and then access wallets connected to the affected Lightning nodes.
A macaroon works as an authentication credential for a Lightning node, with an administrator macaroon providing extensive permissions over the associated wallet. Access to those credentials can therefore allow an unauthorized party to control funds held through the affected LND setup.
BTCPay Server exploit was fixed in version 2.4.2
Following the discovery, BTCPay released the final version of 2.4.2 with a fix for the vulnerability and urged operators running older versions to update their servers.
The project said the security issue was specific to LND credentials and did not expose users running other Lightning implementations through the same attack route. Operators who do not use Lightning were also not affected by the LND credential issue, although BTCPay recommended that all users install the latest release.
BTCPay’s onchain wallets were not compromised through the vulnerability, including onchain hot wallets maintained by users of the software, according to the project.
The distinction limits the known attack path to connected LND wallets rather than the full range of Bitcoin funds that can be managed through a BTCPay installation.
Although BTCPay has yet to release figures for the losses, reports from individual users have confirmed that the exploit resulted in stolen funds. The project is preparing a full postmortem that is expected to provide more information about the vulnerability and the response.
BTCPay has also started introducing stronger code-scanning and review procedures with assistance from several external organizations.
The response follows a difficult year for crypto security. In April,crypto.news reported that CertiK had recorded more than $600 million in crypto losses during 2026 at the time, while the security firm warned that AI-assisted attacks and weaknesses in infrastructure were becoming important risks for projects.
Researchers receive 0.42 BTC for finding the flaw
Alongside the recovery bounty, the BTCPay Server Foundation is paying rewards to the researchers who identified the vulnerability before it was publicly disclosed.
The foundation is donating 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund. Raw discovered the security issue and privately reported it to BTCPay, allowing developers to prepare a fix before details of the flaw became public.
Raw later said he had also been affected by the exploit.
Bitcoin Red Team operates as a volunteer security research group whose members include Rob Hamilton, Calle and Evan Kaloudis. The group works on finding and reporting vulnerabilities affecting Bitcoin-related software.
BTCPay’s decision to fund both researchers comes alongside the separate recovery bounty backed by project supporters. Under the proposed terms, 10% of successfully recovered funds can be paid as a bounty, while a complete recovery would carry a maximum reward of 3 BTC.
Recovery incentives have also surfaced after other crypto exploits this year. In July, crypto.news examined efforts to recover roughly 16 million ADA taken from 374 Cardano wallets in a late-June exploit. EMURGO outlined a process to return affected assets while an independent forensic team conducted a separate investigation into the incident.
AI may have helped uncover the BTCPay Server exploit
As part of its initial assessment, BTCPay raised the possibility that artificial intelligence tools could have played a role in finding the vulnerable code.
The project said improving AI models have reduced the time and cost required to inspect large software repositories for weaknesses, changing the capabilities available to both attackers and security researchers.
Bitcoin software presents an attractive target because exploitable weaknesses can provide direct access to assets, BTCPay said, adding that other areas of the software industry could eventually face similar problems as AI-based code analysis becomes more capable.
Concerns over AI-assisted attacks had already surfaced elsewhere in the crypto sector. CertiK reported in June that crypto hacks and exploits caused $68.3 million in losses during May, down nearly 90% from roughly $650 million in April, but the firm also recorded an increase in AI-assisted malware targeting code repositories and coding tools, as previously covered by crypto.news.
A July analysis of AI security also examined how increasingly capable models can identify and exploit software vulnerabilities, with the technology arriving during a year already dominated by large crypto security incidents.
The BTCPay incident differs from attacks based primarily on social engineering or compromised signing devices because the entry point was a software vulnerability that exposed sensitive LND authentication credentials.
Coldcard exploit raised similar AI concerns
The BTCPay attack has followed another major Bitcoin security incident involving Coldcard hardware wallets, where the suspected use of AI to inspect older code was also raised after funds were stolen.
At least $116 million in losses have been confirmed from the Coldcard exploit so far. Coinkite, the company behind Coldcard, said it considered it likely that someone had used AI to examine older publicly available firmware and identify the weakness.
The two incidents have put code review under increased attention at a time when attackers have already moved beyond conventional smart contract vulnerabilities.
In April, crypto.news reported on more than $17 billion lost across 518 documented crypto hacks and exploits over the previous decade, citing DefiLlama data. The report found that private key leaks, credential theft, phishing and attacks against wallets and infrastructure had become major sources of losses alongside flaws in smart contracts.
Chainalysis has separately estimated that attackers stole $36.7 million from unverified, closed-source smart contracts during the first six months of 2026 by decompiling contract bytecode. The blockchain analytics firm assessed that AI was very likely involved in this activity.
For BTCPay users, the immediate remediation remains the official 2.4.2 release. The project has said it will publish a more detailed postmortem on the exploit while its new code-scanning and review procedures are being developed with external organizations.
You must be logged in to post a comment Login