BTCPay Server supporters offer up to 3 BTC for recovery bounty after critical exploit

摘要:BTCPay Server supporters have pledged a recovery bounty of 10% of recovered funds, capped at 3 BTC, after a critical vulnerability in versions before 2.4.2 let attackers steal LND admin macaroon credentials and control connected Lightning wallets. The open-source bitcoin payments processor urged updates to 2.4.2, though onchain wallets were unaffected. Total stolen funds and affected nodes were not disclosed. The BTCPay Server Foundation donated 0.21 BTC each to researcher Craig Raw and the Bitcoin Red Team for privately reporting the flaw. BTCPay suggested AI is shifting the balance between attackers and defenders, enabling faster discovery of weaknesses. The incident follows the Coldcard exploit with at least $116 million in confirmed losses, also possibly AI-assisted.

Quick Take

  • BTCPay supporters committed to a recovery bounty of 10% of recovered funds, capped at 3 BTC for full recovery.
  • A critical vulnerability in BTCPay versions before 2.4.2 allowed attackers to obtain LND admin macaroon credentials, enabling control of connected wallets and nodes, BTCPay disclosed on Monday.

Supporters of BTCPay Server, the open-source bitcoin payments processor that recently disclosed an exploit, have committed to supporting a recovery bounty of 10% of any funds recovered, capped at 3 BTC for full recovery, according to an announcement on Monday.

BTCPay Server announced on Friday that a critical vulnerability was being actively exploited and urged users to update their servers to version 2.4.2. In a security advisory, the firm noted that all BTCPay versions “prior to 2.4.2, including 2.4.2 release candidates” were vulnerable to the attack.

“The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project wrote on X.

In other words, a security flaw let attackers steal the master access keys from certain Bitcoin payment servers, giving them full control over any linked Lightning wallets. A Lightning macaroon is a digital authentication token and credential file used by bitcoin nodes.

“Users of other Lightning implementations and users who do not use Lightning do not need to update to address this LND credential risk, but we strongly encourage them to update BTCPay Server,” BTCPay said.

The official release of 2.4.2 fixed the vulnerability. Also, BTCPay Server's onchain wallets, including hot wallets, were not affected, the team said.

BTCPay did not publicly disclose the total amount stolen or the number of nodes affected. Some users, like Foundation and Citadel21, said their Lightning nodes were drained.

AI 'changing the balance' between attackers, defenders

The BTCPay Server Foundation is donating 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the critical vulnerability to BTCPay Server.

Raw, the developer of Sparrow Wallet, said he was also affected. The Bitcoin Red Team is a volunteer group of researchers, including members such as Rob Hamilton, Calle, and Evan Kaloudis.

In the announcement, BTCPay said an additional postmortem is in the works, and the team is “introducing more robust code-scanning and review processes with support from several external organizations.”

BTCPay also suggested that AI may have contributed to discovering the vulnerability.

“AI is changing the balance between attackers and defenders. As models improve, it becomes faster and cheaper to inspect large codebases and find weaknesses,” BTCPay wrote. “Bitcoin projects are particularly exposed because they are valuable targets. The rest of the software industry will face the same reality.”

Coldcard fallout continues

Indeed, the attack comes on the heels of the major Coldcard exploit that hit trusted hardware wallets, leading to at least $116 million in confirmed losses so far. Coinkite, the company behind Coldcard, said it was likely that someone used AI to review older public firmware versions and uncover the issue.

Chainalysis estimated that $36.7 million was stolen from unverified, closed-source smart contracts in the first six months of 2026 by decompiling their bytecode, which very likely required AI.

Bitcoin security expert Jameson Lopp previously told The Block that AI is both making it easier to discover code vulnerabilities and execute security reviews.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

亚洲股市上涨 关注周三 CPI 数据

下一篇

Messari:TRON USDT 供應量達 879 億美元,第二季度轉帳額達 2.1 萬億美元

監管中1年內 5.49