In brief
- BTCPay Server supporters offered 10% of recovered funds, capped at 3 BTC.
- Attackers stole Bitcoin using credentials taken from vulnerable LND servers.
- Users running affected software should update to version 2.4.2 immediately.
BTCPay Server supporters are offering 10% of any funds recovered, capped at 3 BTC currently worth around $190,000, if all the Bitcoin stolen in a recent exploit is returned.
In a post on X on Monday, BTCPay said the offer extends to anyone with information that could help recover the funds, including the attacker.
“We will examine our mistakes, but regret alone will not help affected users or secure the project,” the company wrote. “There is no time to waste. We have to learn, improve, and act quickly.”
BTCPay first warned users about the attacks on Friday, urging them to install a new version, 2.4.2, or take their servers offline. At the time, the project had not confirmed any thefts or explained how the exploit worked.
According to BTCPay, the flaw allowed attackers to obtain LND admin macaroons—credentials that grant broad control over a Lightning Network node—and use them to access connected wallets. The Lightning Network is a layer-2 payment network built on the Bitcoin blockchain that enables faster and cheaper transactions. Lightning Network nodes route payments through channels between users.
BTCPay has not disclosed how much Bitcoin was stolen, how many users were affected, or whether any funds have been recovered.
If multiple tips help recover the funds, the bounty will be divided in coordination with victims. The project said it would consider each victim’s losses, the amount recovered, and the usefulness of each tip.
The BTCPay Server Foundation will also donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for responsibly disclosing the vulnerability.
“These are modest contributions, but they are what we can offer as a FOSS project and a way to appreciate people doing critical security work, which helps the entire ecosystem,” BTCPay wrote.
The company said it is strengthening code reviews and prioritizing security patches over new features as AI is making it easier for attackers to find vulnerabilities in Bitcoin software.
“Defending software in this environment requires better tools, more thorough reviews, faster security responses, and support for researchers who find and responsibly report vulnerabilities,” BTCPay wrote.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.