Supporters of the open-source Bitcoin payment processor BTCPay Server have committed to a recovery bounty of up to 3 BTC following a critical exploit that allowed attackers to drain connected Lightning wallets. The bounty offers 10% of any recovered funds, capped at 3 BTC if full recovery is achieved.
The vulnerability, disclosed on Friday, affected all BTCPay Server versions prior to 2.4.2 — including release candidates. The project warned that the flaw enabled attackers to obtain LND admin macaroon credentials from vulnerable instances, granting full control over linked Lightning Network wallets. On-chain wallets, including hot wallets, were not impacted. Users of other Lightning implementations or those not using Lightning were also safe, but the project strongly urged all operators to update immediately.
BTCPay Server did not disclose the total amount stolen, but community members reported drained Lightning nodes. The BTCPay Server Foundation is donating 0.21 BTC each to security researcher Craig Raw (who discovered the issue) and the Bitcoin Red Team for responsible disclosure.
In a statement, the project said a postmortem is underway and that it is introducing more robust code-scanning and review processes with support from external organizations. The incident also sparked discussion about AI’s role in vulnerability discovery, with BTCPay noting that “AI is changing the balance between attackers and defenders” and making it faster to inspect large codebases. The exploit follows a major Coldcard hardware wallet breach that led to over $116 million in confirmed losses, raising concerns about Bitcoin infrastructure security.