Bitcoin holds steady at US$64,000 after attack on BTCPay Server Lightning Wallet
On Monday, bitcoin trading prices were close to US$64,000. Although BTCPay Server, a popular open source cryptocurrency payment platform, suffered a serious security breach, the price fluctuated little. The incident prompted the BTCPay community to offer a recovery reward of up to 3 BTC to recover stolen funds. Previously, attackers used a key vulnerability in the software to carry out the attack.
Lightning Internet users targeted by security breaches
BTCPay Server disclosed on August 7 that an active vulnerability was attacking its users and urged an immediate upgrade to version 2.4.2 or a temporary shutdown of the server to reduce risk. Reports from organizations such as the Foundation and Citadel21 show that their lightning nodes were affected, but BTCPay did not disclose the total damage or the number of nodes attacked.
Developers pointed out that online wallets (including hot money packages) within BTCPay were not affected. Attackers specifically target vulnerable server instances and obtain LND administrator macaroon credentials, allowing them to control the recipient's lightning wallet.
BTCPay supporters promise to provide a reward of up to 3 BTC, equivalent to 10% of any recovered funds, as an incentive to return stolen bitcoins. In addition, the BTCPay Server Foundation awarded 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team Foundation for their private disclosure of the vulnerability.
Sparrow wallet developer Craig Raw said he was one of the people affected by the vulnerability. The vulnerability affects all BTCPay Server versions earlier than 2.4.2 (including candidate versions). No CVE identifier has been assigned to this event.
Details of the macaroon vulnerability
The core problem lies in macaroons, an authentication certificate used by the LND. Once exposed, attackers can fully control the relevant Lightning nodes and their funds. To completely fix it, operators not only need to update to the latest version, but also must regenerate all lightning certificates and replace existing macaroons, because stolen certificates will remain valid until they are replaced in the database.
Administrators should access the maintenance tool through Management Dashboard → Server → Maintenance → Updates, ensuring that the footer displays "2.4.2". Until then, operators are advised to keep the server offline if updates cannot be applied immediately.
The latest patch also fixes an unrelated TOTP two-factor authentication bypass vulnerability, but the actively exploited vulnerability is limited to LND macaroon credentials.
Broader impact on Bitcoin infrastructure
The vulnerability exposed key issues in application-layer software rather than Bitcoin's own protocols or encryption technology. As a result, the core Bitcoin network is operating fully normally and there is no evidence of damage.
According to BuiltWith statistics, BTCPay Server has historically been used by 248 websites, and there are still 74 active sites, but private installations do not count in these numbers. At the same time, 1ML data shows that there are approximately 5,585 active lightning nodes, and a total of approximately 2,640 BTC in these channels. River reported that merchants 'adoption of Bitcoin increased by 74% in 2025, with monthly transactions conducted through the Lightning Network exceeding US$1 billion.
Continuous monitoring of credentials and infrastructure is critical to ecosystems. In the context of managing crypto assets, there is a growing need for seamless access to real-world investments. Some platforms have moved real-world assets, including stocks of major U.S. companies, as well as gold and silver, onto blockchain networks, providing instant access and optimal pricing, helping users diversify their investments with minimum complexity without relying on intermediaries.
The emerging role of AI in security
BTCPay points out that AI has an increasing influence in the field of software security. Although advanced AI-assisted code analysis can speed up vulnerability detection by defenders, it also allows attackers to review large codebases at a lower cost.
The impact of this dynamic is not limited to payment platforms. A recent vulnerability involving Coldcard's hardware wallet resulted in the loss of 1,816 BTC from more than 5,200 addresses and prompted the company to change its data retention policies.
Chainalysis observes that AI-driven analysis and automated smart contract review tools have the potential to accelerate the discovery and utilization of loosely censored code, making it easier for malicious actors to launch large-scale attacks.
For Bitcoin's broader infrastructure, the incident highlights that as AI further accelerates the discovery and exploitation of vulnerabilities, organizations must proactively strengthen code quality and credential management to reduce the impact of future events.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC