EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

A $190,000 Bitcoin reward is pending, and thieves are sincerely invited to come and collect it.

2026-08-13 15:45:21
Bookmark

BTCPay Server reveals serious vulnerability and user funds have been stolen.

BTCPay Server is a free, self-hosted open source software that many merchants use to accept Bitcoin payments. On August 7, the project disclosed that a serious vulnerability was being actively exploited to attack active servers, and some users had suffered financial losses.

The project stated that the vulnerability allowed an attacker to obtain LND administrator credentials (admin macaroon) from affected instances and then access the Lightning network wallet connected to it. Simply put, this vulnerability allows attackers to grasp the lightning node key behind the merchant payment server, allowing them to transfer funds. The vulnerability affects all versions before version 2.4.2. Identified victims include Passport hardware wallet maker Foundation and media organization Citadel21, whose nodes were looted before the public warning was issued. BTCPay has not disclosed the total amount of stolen funds or the number of servers affected.

Technical details and repair steps have been released in a safety bulletin. Users who have not yet upgraded should immediately update to version 2.4.2, which also refreshes the LND and regenerates administrator credentials. Crucially, the project warns that upgrades alone are not enough: patches can block new access but cannot invalidate leaked credentials, so operators must also revoke their LND credentials and move funds out of any hot wallets generated by BTCPay.

"We are deeply sorry for the users who have suffered financial losses. We will review our own mistakes, but regret alone cannot help affected users or ensure project safety. Time is running out, and we must learn, improve and act quickly."

Recovery Bounty Details

Supporters and friends of the project have promised a bounty of 10% of the funds recovered, with a maximum of 3 bitcoins-approximately US$190,000 at recent prices-provided the funds are repaid in full. Anyone with effective information that can facilitate financial recovery can participate, including the attacker himself. If necessary, communicate through secure channels such as Signal. If multiple clues come into play, the reward will be coordinated and distributed with the victim based on factors such as the usefulness of the information, the loss and the amount recovered.

In addition, the BTCPay Server Foundation donated 0.21 Bitcoin to Sparrow Wallet developer Craig Raw and 0.21 Bitcoin to the Bitcoin Red Team Fund in recognition of their responsible disclosure of the vulnerability. Raw discovered the problem and reported it privately, buying the development team time to prepare the fix before the details were made public.

"The BTCPay Server Foundation will donate 0.21 Bitcoin to Craig Raw and 0.21 Bitcoin to the Bitcoin Red Team Fund to thank them for their responsible disclosure of the vulnerability. These are limited contributions."

Next steps for affected users

Affected users who have not yet reported should submit their on-chain addresses and transaction details to the project's secure address via email. The project also recommends that users report cases to local law enforcement and contact relevant exchanges or service providers where stolen funds may be discovered; personal reporting helps build a clearer chain of evidence and increases the possibility of freezing funds.

BTCPay Server said it is working with the exchange security team, blockchain analytics companies and law enforcement agencies. In the future, the project will prioritize security patches and hardening rather than developing new features, and recommends that users store excess funds in cold wallets rather than hot wallets connected to payment servers.

The team said the incident highlights the growing challenges faced in protecting open source Bitcoin software as artificial intelligence tools make vulnerability discovery faster and cheaper. It also came at a difficult time for Bitcoin's infrastructure-just days after another attack related to a firmware vulnerability cost Coldcard hardware wallet users tens of millions of dollars.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP