BTCPay Server Community Pledges Recovery Reward of Up to 3 Bitcoin (BTC) After Critical Vulnerability Was Exploited

Following a significant security breach affecting the open-source Bitcoin payment platform, members of the BTCPay Server community have stepped forward with a substantial incentive aimed at reclaiming lost assets.

Supporters of the project have pledged a recovery bounty structured as 10 percent of any funds successfully returned, with the total reward limited to a maximum of 3 Bitcoin should a complete recovery occur.

The incident stems from a critical flaw in BTCPay Server installations running versions earlier than 2.4.2, including certain release candidates of that update. This vulnerability enabled remote attackers without authentication to obtain

administrative macaroon credentials associated with LND, a widely used implementation of the Lightning Network.

Once in possession of these credentials, the attackers gained the ability to control connected Lightning nodes and drain associated wallets.

On-chain wallets managed through BTCPay Server itself remained unaffected by the issue.

BTCPay Server publicly disclosed the active exploitation of the vulnerability around August 7, 2026, and strongly advised operators to upgrade immediately to version 2.4.2 or temporarily take their servers offline.

The patched release addresses the flaw, upgrades the integrated LND component, and automatically regenerates the relevant credentials in standard setups.

Users were also urged to review node activity for unauthorized transactions, unexpected channel closures, or unfamiliar peers, and to rotate credentials where custom configurations were in place.

Although the project has not released official figures on the total value of assets taken or the number of impacted nodes, several users confirmed losses.

Among those reporting drained Lightning nodes were Foundation, the hardware wallet manufacturer, and Citadel21.

The precise scale of the impact continues to be assessed.

In response, the BTCPay Server Foundation has recognized the researchers who identified and privately reported the issue.

It is donating 0.21 Bitcoin to Craig Raw, the developer of Sparrow Wallet, and another 0.21 Bitcoin to the Bitcoin Red Team fund.

These contributions acknowledge the responsible disclosure that allowed time for a fix to be prepared.

Separately, friends and supporters of the project have committed resources to the recovery bounty.

The offer extends to anyone providing actionable information that helps return the funds, explicitly including the attacker. Interested parties are directed to contact security@btcpayserver.org, with options available for secure channels such as Signal upon request.

In cases where multiple sources contribute to a successful recovery, the reward will be divided in coordination with victims, taking into account individual losses, the volume of funds reclaimed, and the usefulness of each contribution.

Project representatives have expressed regret to those affected, emphasizing that while mistakes will be reviewed, the priority remains practical action, rapid improvement, and enhanced security.

A comprehensive postmortem is expected in the coming period, alongside stronger code-scanning and review processes involving external partners.

The team has indicated that security-focused work will take precedence over new feature development for the foreseeable future.

This coordinated effort highlights the collaborative nature of the Bitcoin open-source ecosystem, where community members, researchers, and the project itself work to mitigate damage and reinforce defenses following a serious incident. Operators are reminded to ensure their systems are fully updated and to remain vigilant regarding Lightning node security.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend