BTCPay Server is offering a 10% recovery bounty capped at 3 BTC — roughly $190,000 — after attackers exploited an LND credential flaw to drain merchant Lightning wallets last week.
BTCPay Server is offering a 10% recovery bounty capped at 3 BTC — roughly $190,000 — after attackers exploited an LND credential flaw to drain merchant Lightning wallets last week.

BTCPay Server is offering a 10% recovery bounty capped at 3 BTC, worth roughly $190,000, after attackers drained merchant Lightning wallets last week.
The offer is open to anyone with useful information, including the attacker, BTCPay Server said in an X post on Aug. 10. If several reports lead to a recovery, the bounty will be split with the victims according to how much each lost and how useful the information proved.
Attackers exploited a critical vulnerability to obtain LND admin macaroon credentials — files that grant software permission to control a Lightning node — and drain connected wallets. Hardware-wallet maker Foundation and bitcoin publication Citadel21 both reported losses. BTCPay has not disclosed the total amount stolen or the number of affected users.
The project is also donating 0.21 BTC each to developer Craig Raw and the Bitcoin Red Team fund for responsibly disclosing the flaw. BTCPay said exchanges, blockchain analytics firms and law enforcement have offered help tracing the funds, and urged affected merchants to report thefts to local police.
The vulnerability affected all BTCPay Server versions before 2.4.2, including release candidates, and allowed unauthenticated remote attackers to obtain LND ".macaroon" credential files. BTCPay's standard on-chain wallets, including hot wallets generated inside the platform, were not affected. However, funds held in LND's own on-chain wallet remain at risk because they sit under the compromised Lightning node.
Version 2.4.2, released Friday, upgrades standard deployments to LND 0.21.1 and automatically regenerates macaroon credentials. The release also temporarily removes public access to the LND API on Docker deployments, meaning external wallets like Zeus cannot connect through a BTCPay domain or Tor onion address. Normal Lightning payments can continue. The update also tightens Greenfield API security, including a fix for a TOTP two-factor-authentication bypass through Basic authentication, which is now disabled by default five minutes after account creation.
The Bitcoin Red Team — a volunteer group of developers using AI models to scan bitcoin codebases — reported the flaw to BTCPay before it was exploited. Members Craig Raw, Rob Hamilton, Calle and Evan Kaloudis were credited with the responsible disclosure. The group has filed thousands of findings across hundreds of projects since beginning its AI-assisted audit this month.
The incident follows a rough week for bitcoin infrastructure security. Coldcard hardware wallets suffered at least $116 million in confirmed losses after an attacker may have used AI to review older public firmware. Chainalysis separately estimated $36.7 million was stolen from unverified, closed-source smart contracts in the first half of 2026 through attacks involving decompiled bytecode.
BTCPay said AI is changing the economics of vulnerability discovery, making it faster and cheaper to inspect large codebases. "Bitcoin projects are particularly exposed because they are valuable targets," the project said. "The rest of the software industry will face the same reality."
Bitcoin traded at $63,968 as of 02:19 UTC on Aug. 11, down 1.97 percent over 24 hours, as the security incident weighed on sentiment. A full postmortem on the BTCPay vulnerability is expected in the coming days.
This article is for informational purposes only and does not constitute investment advice.