EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BTCPay Server supporters offer a reward of 10% for recovering stolen Bitcoin

2026-08-13 15:46:41
Bookmark

BTCPay Server supporters have set up a vulnerability reward and can receive up to 3 BTC rewards.

BTCPay Server supporters have set up a recovery reward for the recent Lightning Internet Wallet vulnerability incident. The reward amount is 10% of the funds successfully recovered. If all stolen assets are recovered, the reward limit is 3 BTC.

Event summary

This vulnerability resulted in the disclosure of LND administrator macaroon credentials, allowing attackers to access the affected Lightning network wallet. BTCPay has fixed the vulnerability in version 2.4.2, but online wallets have not been affected. The BTCPay Server Foundation donated 0.21 BTC to the Craig Raw and Bitcoin Red Team Funds, which discovered and reported the vulnerability. BTCPay said that artificial intelligence may have contributed to the discovery of the vulnerability and is currently preparing a detailed summary report.

Vulnerability Details and Impact

The BTCPay Server project said on Monday that the bounty program is part of its response to critical security vulnerabilities. The vulnerability resulted in the exposure of LND administrator credentials in the affected installation environment. In the past few days, users have been asked to immediately upgrade to version 2.4.2. The open source Bitcoin payment processor has not disclosed the specific amount of cryptocurrency stolen or the number of servers affected. However, multiple affected users, including Foundation and Citadel21, reported that funds from their Lightning nodes had been stolen.

BTCPay said the vulnerability affects all releases prior to version 2.4.2, including release candidates for 2.4.2. The vulnerability allows an attacker to obtain LND administrator macaroon credentials from exposed BTCPay instances and then access wallets connected to affected Lightning nodes. Macaroon serves as the authentication certificate of the lightning node, and the administrator macaroon grants extensive permissions to the associated wallet. Therefore, the disclosure of these credentials can allow unauthorized parties to control funds in the affected LND settings.

Bug fixes and responses

After the vulnerability was discovered, BTCPay released an official version of 2.4.2 containing fixes and urged operators running older versions to update their servers. The project party stated that the security issue was limited to LND credentials and did not affect operators using other Lightning network implementations through the same attack path. Operators who do not use the Lightning Network feature are also not affected by this LND credential issue. Despite this, BTCPay still recommends that all users install the latest version.

According to the project, BTCPay's on-chain wallets (including on-chain hot wallets maintained by users) are not affected by this vulnerability. This restriction limits known attack paths to connected LND wallets, rather than all Bitcoin funds managed through BTCPay installations. Although BTCPay has not released loss data, reports from individual users have confirmed that the vulnerability led to the theft of funds. The project party is preparing a comprehensive summary report, which is expected to provide more information on vulnerabilities and countermeasures. BTCPay has also begun to introduce a more stringent code scanning and review process with the assistance of a number of external organizations.

Researchers receive a 0.42 BTC reward for discovering vulnerabilities

In addition to the recovery reward, the BTCPay Server Foundation also awarded rewards to researchers who identified the issue before the vulnerability was publicly disclosed. The foundation donated 0.21 BTC each to Sparrow Wallet developer Craig Raw and Bitcoin Red Team funds. Raw discovered the security issue and privately reported it to BTCPay, allowing developers to prepare fixes before details of the vulnerability are made public. Raw later said he himself was affected by the breach. The Bitcoin Red Team is a volunteer security research group that includes Rob Hamilton, Calle and Evan Kaloudis dedicated to discovering and reporting vulnerabilities in bitcoin-related software.

While BTCPay decided to fund the two researchers, it also launched an independent recovery bounty program supported by project supporters. According to the proposed terms, 10% of the funds successfully recovered can be paid as a reward, and a maximum of 3 BTC will be awarded for full recovery.

Artificial intelligence may help discover vulnerabilities

As part of its preliminary assessment, BTCPay raised the possibility that artificial intelligence tools may have played a role in discovering vulnerable code. Projects say that continuously improving AI models have reduced the time and cost required to inspect large software codebases to discover vulnerabilities, changing the scope of capabilities of attackers and security researchers. BTCPay points out that Bitcoin software has become an attractive target because exploitable weaknesses can directly provide access to assets. As AI-based code analysis capabilities continue to increase, other areas of the software industry may eventually face similar problems.

Concerns about AI-assisted attacks have previously emerged in other aspects of the encryption space. Unlike attacks that are mainly based on social engineering or signature device damage, the BTCPay incident has a software vulnerability that exposes sensitive LND authentication credentials.

Coldcard vulnerability raises similar AI concerns

BTCPay attack follows another major Bitcoin security incident involving Coldcard's hardware wallet. In this incident, after the funds were stolen, some people also suspected that AI was used to check old code. The Coldcard vulnerability has been confirmed to have cost at least $116 million. Coinkite, the company behind Coldcard, said it believed it was likely that someone had used AI to examine older public firmware and identify the vulnerability.

These two incidents brought more attention to code censorship at a time when attackers have moved beyond traditional smart contract vulnerabilities. For BTCPay users, the current remedy is still to install the official version 2.4.2. The project said it would release a more detailed summary report on the vulnerability and was working with external organizations to develop a new code scanning and review process.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP