Bitcoin prices were stable on Monday, BTCPay Server vulnerabilities attracted attention
On Monday, Bitcoin prices remained almost unchanged, trading at around $64,000. At the same time, supporters of BTCPay Server have promised a reward of up to 3 BTC to recover funds stolen due to key flaws in the open source payment software. The lack of enthusiasm in the market means traders may view the incident as a threat to merchants and Lightning network users rather than a threat to Bitcoin itself. According to market data, the market value of Bitcoin is estimated to be US$1.28 trillion, a drop of approximately 0.5%. The hack affected software built on Bitcoin, not the Bitcoin network itself.
Prices remain stable and some lightning nodes are stolen.
On August 7, BTCPay Server disclosed that the vulnerability is being actively exploited and urged users to upgrade to version 2.4.2 or stop the server before fixing the problem. Users reported to have been attacked on its Lightning node include Foundation and Citadel21. However, BTCPay did not provide the total loss amount or the number of nodes affected. The project said its own on-chain wallets, including hot money packages, were not affected. Instead, an attacker could obtain LND administrator macaroon credentials from a vulnerable BTCPay instance and use these credentials to control connected lightning wallets.
Supporters offer 10% recovery reward
To help victims recover funds, BTCPay supporters promise to provide a reward equivalent to 10% of the stolen funds recovered, with a maximum of 3 BTC if fully recovered. The BTCPay Server Foundation also donated 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team Foundation to reward them for discovering and privately reporting the vulnerability. Raw, developer of Sparrow Wallet, said he was also one of those affected.
What can an attacker do by macaroon vulnerability
All versions of BTCPay Server prior to version 2.4.2, including release candidate versions for that version, are at risk for LND credentials. BTCPay has not publicly assigned a CVE identifier to this event. Macaroon is an authentication credential used by LND to authorize API access. The vulnerability allows a malicious user to obtain LND administrator macaroon from an affected server, thereby taking control of associated lightning nodes and wallets. The update mechanism should be accessed through "Management Panel → Server → Maintenance → Updates", and the operator can check whether the footer displays 2.4.2. If it cannot be updated immediately, BTCPay recommends shutting down the server. Applying patches alone may not be enough, and operators must refresh their lightning credentials and macaroon because leaked credentials may still be valid. According to the LND documentation, deleting the macaroon file does not invalidate previously issued certificates-the macaroon database must also be replaced. 2.4.2 The version also fixes a vulnerability reported on August 4 that bypasses TOTP two-factor authentication through Greenfield Basic Authentication, but the issue is not related to the currently exploited LND vulnerability.
Why peripheral software is a weak link
The incident is mainly an infrastructure issue because the flaws involved lie in the application layer of BTCPay, rather than the consensus rules or cryptography on which Bitcoin relies. As a result, the Bitcoin network continued to operate normally without any problems. However, the scope of influence is still not small. Statistics show that 248 websites have used BTCPay Server at various times, including 74 websites that are still in operation, but these statistics do not cover private installations. At the same time, the Lightning Network Data Platform reported that there are currently approximately 5,585 active Lightning nodes, of which the total amount of BTC available is approximately 2,640 BTC. An organization said that the adoption rate of Bitcoin by merchants will increase by 74% in 2025, and the monthly transaction volume on the Lightning Network has exceeded US$1 billion.
AI's dual role in exploit
BTCPay said the incident also highlighted how AI can change software security. Better AI-assisted code analysis can help defenders discover vulnerabilities faster, but it also reduces the cost for attackers to inspect large open source code bases. This concern is not limited to payment software. A recent hardware wallet vulnerability resulted in the theft of approximately 1,816 BTC from more than 5,200 addresses. The impact is not limited to stolen funds. The company also temporarily changed its data retention policy. Blockchain analytics companies have also warned that AI-assisted analysis and simpler smart contract decompilation could make it easier to scale attacks on poorly censored code. For Bitcoin infrastructure, the lesson is deeper than a single vulnerability: AI can speed up vulnerability discovery, but a successful attack can have consequences far beyond code breaches, from wallet theft and payment interruptions to investigations and changes in the way companies handle customer data.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC