BTCPay Server Supporters Offer Recovery Bounty After Lightning Wallet Exploit
Supporters of BTCPay Server have committed to paying a bounty equal to 10% of any stolen funds recovered following a critical exploit, capped at 3 BTC if all funds are returned.
The vulnerability affected every BTCPay Server version before 2.4.2, including release candidates. It allowed attackers to obtain LND administrator macaroons—authentication credentials granting full access to connected Lightning wallets. Several users reported that their Lightning nodes had been drained, although BTCPay has not disclosed the total losses or number of affected servers.
Version 2.4.2 fixes the vulnerability. Users without Lightning or those running other Lightning implementations were not exposed to this specific risk, while BTCPay’s on-chain wallets, including hot wallets, were unaffected.
The BTCPay Server Foundation will also donate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the flaw. BTCPay is preparing a full postmortem and strengthening its code-scanning and review procedures.
The project warned that artificial intelligence is lowering the cost of examining large codebases for vulnerabilities, giving both attackers and defenders more powerful security tools. $BTC