BTCPay Server provides a 3 BTC reward to recover stolen bitcoins
BTCPay provides a reward of 10% of the recovered funds, with a maximum of 3 BTC. The attacker used leaked LND administrator credentials to steal funds from Lightning Internet Wallet. Craig Raw and Bitcoin Red Team will each receive 0.21 BTC for disclosing the vulnerability. Backers of BTCPay Server have funded a bounty program aimed at recovering bitcoins stolen from merchants during last week's security breach. The reward is 10% of the recovered funds, with a maximum payment of 3 BTC. The project is open to anyone with useful information, including the attacker himself. Victims reported that Lightning's Internet wallet was looted, but the total amount of damage has not been disclosed.
BTCPay Server Bounty Program seeks to recover stolen bitcoins
BTCPay Server's recovery program will reward information that directly helps return stolen funds. Contributors can be contacted through the project security team, which also provides secure communication channels. If multiple reports help recover funds, the project will distribute the reward to contributors and victims. The amount paid will reflect the loss of each victim and the value of the information provided.
BTCPay Server donated 0.21 BTC to Craig Raw and 0.21 BTC to the Bitcoin Red Team in recognition of their responsible disclosure of recent critical vulnerabilities. In addition, friends and supporters of the BTCPay Server project have pledged to fund a bounty to recover stolen bitcoins.
The bounty program was released after the Foundation and Citadel21 reported that attackers cleared its Lightning network nodes. Exchanges, blockchain analytics companies and law enforcement agencies have also provided support to assist in tracing stolen bitcoins. BTCPay has asked affected merchants to report to local police. Users should also contact relevant services so that investigators can track stolen funds.
BTCPay Server fixes critical LND credential vulnerability
This attack targets a vulnerability that affects versions of BTCPay Server before 2.4.2. Attackers can obtain LND administrator macaroon credentials from exposed installations. These credentials provide extensive access to connected Lightning Network Wallets. This vulnerability does not expose BTCPay's on-chain wallet through the same attack path. The final release of BTCPay Server 2.4.2 fixed the LND vulnerability. The project urges affected operators to upgrade immediately.
BTCPay also rewards researchers who privately report the vulnerability. Sparrow Wallet developer Craig Raw and Bitcoin Red Team will each receive 0.21 BTC. The BTCPay Server team is preparing a complete post-mortem analysis report and is working with external security teams to enhance the code scanning and review process.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC