BTCPay Server supporters offer up to 3 BTC for recovery bounty after critical exploit

خلاصہ:BTCPay Server supporters have pledged a recovery bounty of 10% of recovered funds, capped at 3 BTC, after a critical vulnerability in versions before 2.4.2 let attackers steal LND admin macaroon credentials and control connected Lightning wallets. The open-source bitcoin payments processor urged updates to 2.4.2, though onchain wallets were unaffected. Total stolen funds and affected nodes were not disclosed. The BTCPay Server Foundation donated 0.21 BTC each to researcher Craig Raw and the Bitcoin Red Team for privately reporting the flaw. BTCPay suggested AI is shifting the balance between attackers and defenders, enabling faster discovery of weaknesses. The incident follows the Coldcard exploit with at least $116 million in confirmed losses, also possibly AI-assisted.

Quick Take

  • BTCPay supporters committed to a recovery bounty of 10% of recovered funds, capped at 3 BTC for full recovery.
  • A critical vulnerability in BTCPay versions before 2.4.2 allowed attackers to obtain LND admin macaroon credentials, enabling control of connected wallets and nodes, BTCPay disclosed on Monday.

Supporters of BTCPay Server, the open-source bitcoin payments processor that recently disclosed an exploit, have committed to supporting a recovery bounty of 10% of any funds recovered, capped at 3 BTC for full recovery, according to an announcement on Monday.

BTCPay Server announced on Friday that a critical vulnerability was being actively exploited and urged users to update their servers to version 2.4.2. In a security advisory, the firm noted that all BTCPay versions “prior to 2.4.2, including 2.4.2 release candidates” were vulnerable to the attack.

“The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project wrote on X.

In other words, a security flaw let attackers steal the master access keys from certain Bitcoin payment servers, giving them full control over any linked Lightning wallets. A Lightning macaroon is a digital authentication token and credential file used by bitcoin nodes.

“Users of other Lightning implementations and users who do not use Lightning do not need to update to address this LND credential risk, but we strongly encourage them to update BTCPay Server,” BTCPay said.

The official release of 2.4.2 fixed the vulnerability. Also, BTCPay Server's onchain wallets, including hot wallets, were not affected, the team said.

BTCPay did not publicly disclose the total amount stolen or the number of nodes affected. Some users, like Foundation and Citadel21, said their Lightning nodes were drained.

AI 'changing the balance' between attackers, defenders

The BTCPay Server Foundation is donating 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the critical vulnerability to BTCPay Server.

Raw, the developer of Sparrow Wallet, said he was also affected. The Bitcoin Red Team is a volunteer group of researchers, including members such as Rob Hamilton, Calle, and Evan Kaloudis.

In the announcement, BTCPay said an additional postmortem is in the works, and the team is “introducing more robust code-scanning and review processes with support from several external organizations.”

BTCPay also suggested that AI may have contributed to discovering the vulnerability.

“AI is changing the balance between attackers and defenders. As models improve, it becomes faster and cheaper to inspect large codebases and find weaknesses,” BTCPay wrote. “Bitcoin projects are particularly exposed because they are valuable targets. The rest of the software industry will face the same reality.”

Coldcard fallout continues

Indeed, the attack comes on the heels of the major Coldcard exploit that hit trusted hardware wallets, leading to at least $116 million in confirmed losses so far. Coinkite, the company behind Coldcard, said it was likely that someone used AI to review older public firmware versions and uncover the issue.

Chainalysis estimated that $36.7 million was stolen from unverified, closed-source smart contracts in the first six months of 2026 by decompiling their bytecode, which very likely required AI.

Bitcoin security expert Jameson Lopp previously told The Block that AI is both making it easier to discover code vulnerabilities and execute security reviews.

ڈس کلیمر

یہ مضمون صرف مصنف کی ذاتی رائے پر مبنی ہے، یہ پلیٹ فارم کی سرمایہ کاری کی مشورہ نہیں ہے۔ پلیٹ فارم مضمون کی معلومات کی درستگی، مکملیت اور بروقت ہونے کی کوئی ضمانت نہیں دیتا، اور مضمون کی معلومات پر اعتماد یا استعمال سے ہونے والے کسی بھی نقصان کی ذمہ داری قبول نہیں کرتا۔
ریگولیشن جاری ہے1 سال کے اندر 5.49