BTCPay Server supporters offer up to 3 BTC for recovery bounty after critical exploit

Lời nói đầu:BTCPay Server supporters have pledged a recovery bounty of 10% of recovered funds, capped at 3 BTC, after a critical vulnerability in versions before 2.4.2 let attackers steal LND admin macaroon credentials and control connected Lightning wallets. The open-source bitcoin payments processor urged updates to 2.4.2, though onchain wallets were unaffected. Total stolen funds and affected nodes were not disclosed. The BTCPay Server Foundation donated 0.21 BTC each to researcher Craig Raw and the Bitcoin Red Team for privately reporting the flaw. BTCPay suggested AI is shifting the balance between attackers and defenders, enabling faster discovery of weaknesses. The incident follows the Coldcard exploit with at least $116 million in confirmed losses, also possibly AI-assisted.

Quick Take

  • BTCPay supporters committed to a recovery bounty of 10% of recovered funds, capped at 3 BTC for full recovery.
  • A critical vulnerability in BTCPay versions before 2.4.2 allowed attackers to obtain LND admin macaroon credentials, enabling control of connected wallets and nodes, BTCPay disclosed on Monday.

Supporters of BTCPay Server, the open-source bitcoin payments processor that recently disclosed an exploit, have committed to supporting a recovery bounty of 10% of any funds recovered, capped at 3 BTC for full recovery, according to an announcement on Monday.

BTCPay Server announced on Friday that a critical vulnerability was being actively exploited and urged users to update their servers to version 2.4.2. In a security advisory, the firm noted that all BTCPay versions “prior to 2.4.2, including 2.4.2 release candidates” were vulnerable to the attack.

“The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project wrote on X.

In other words, a security flaw let attackers steal the master access keys from certain Bitcoin payment servers, giving them full control over any linked Lightning wallets. A Lightning macaroon is a digital authentication token and credential file used by bitcoin nodes.

“Users of other Lightning implementations and users who do not use Lightning do not need to update to address this LND credential risk, but we strongly encourage them to update BTCPay Server,” BTCPay said.

The official release of 2.4.2 fixed the vulnerability. Also, BTCPay Server's onchain wallets, including hot wallets, were not affected, the team said.

BTCPay did not publicly disclose the total amount stolen or the number of nodes affected. Some users, like Foundation and Citadel21, said their Lightning nodes were drained.

AI 'changing the balance' between attackers, defenders

The BTCPay Server Foundation is donating 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the critical vulnerability to BTCPay Server.

Raw, the developer of Sparrow Wallet, said he was also affected. The Bitcoin Red Team is a volunteer group of researchers, including members such as Rob Hamilton, Calle, and Evan Kaloudis.

In the announcement, BTCPay said an additional postmortem is in the works, and the team is “introducing more robust code-scanning and review processes with support from several external organizations.”

BTCPay also suggested that AI may have contributed to discovering the vulnerability.

“AI is changing the balance between attackers and defenders. As models improve, it becomes faster and cheaper to inspect large codebases and find weaknesses,” BTCPay wrote. “Bitcoin projects are particularly exposed because they are valuable targets. The rest of the software industry will face the same reality.”

Coldcard fallout continues

Indeed, the attack comes on the heels of the major Coldcard exploit that hit trusted hardware wallets, leading to at least $116 million in confirmed losses so far. Coinkite, the company behind Coldcard, said it was likely that someone used AI to review older public firmware versions and uncover the issue.

Chainalysis estimated that $36.7 million was stolen from unverified, closed-source smart contracts in the first six months of 2026 by decompiling their bytecode, which very likely required AI.

Bitcoin security expert Jameson Lopp previously told The Block that AI is both making it easier to discover code vulnerabilities and execute security reviews.

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

Grayscale 静悄悄地放弃了 Cardano、Polkadot 和 Hedera 的 ETF 计划

Bài tiếp theo

Tại sao cổ phiếu Nvidia giảm vào thứ Hai dù có thỏa thuận AI trị giá 500 tỷ USD trên Phố Wall?

Có giám sát quản lýTrong vòng 1 năm 5.49