- BTCPay Server offers 10% of recovered funds as a bounty, capped at 3 BTC worth roughly $190,000.
- Attackers stole Bitcoin by exploiting LND admin macaroons from vulnerable Lightning Network nodes.
- The project urges all users to update to version 2.4.2 or take servers offline immediately.
BTCPay Server announced a bounty for information leading to the recovery of Bitcoin stolen in a recent exploit, offering 10% of recovered funds capped at 3 BTC. The open-source payment processor disclosed the attack on Friday and urged users to update to version 2.4.2 or disconnect their servers.
Attackers obtained LND admin macaroons from vulnerable servers, granting broad control over Lightning Network nodes and connected wallets. According to a post on X, the bounty extends to anyone with helpful information, including the attacker themselves.
“We will examine our mistakes, but regret alone will not help affected users or secure the project,” the company wrote. “There is no time to waste. We have to learn, improve, and act quickly.”
BTCPay has not disclosed how much Bitcoin was stolen or how many users were affected. If multiple tips help recover funds, the bounty will be divided based on each victim’s losses and the usefulness of each tip.
The BTCPay Server Foundation will also donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for responsibly disclosing the vulnerability. “These are modest contributions, but they are what we can offer as a FOSS project,” the company stated.
Consequently, the project is strengthening code reviews and prioritizing security patches over new features. BTCPay noted that AI is making it easier for attackers to find vulnerabilities in Bitcoin software, requiring faster security responses and better tools.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
