Security Incident
BTCPay Server Offers $190,000 Bounty Following Lightning Wallet Exploit
According to CoinDesk, BTCPay Server has established a recovery bounty up to 3 BTC after malicious actors compromised LND credentials and drained merchant Lightning wallets last week, an incident that is not officially confirmed by independent law enforcement bodies.

Exploit Overview and Bounty Launch
CoinDesk reported that payment server project BTCPay Server introduced a financial reward program aimed at recovering digital assets stolen during a recent security breach. The initiative offers a bounty equivalent to 10% of any retrieved funds, capped at 3 BTC, which translates to approximately $190,000 at prevailing market valuations. This incentive structure is open to any individual or entity capable of providing actionable intelligence that results in the successful return of the misappropriated cryptocurrency, explicitly including the perpetrators responsible for the breach itself.
According to the same reporting, the security breakdown materialized when unidentified malicious actors managed to acquire confidential credentials associated with LND, which functions as the primary software framework for deploying Lightning network nodes. These unauthorized access vectors allowed the attackers to systematically drain connected merchant wallets. Prominent entities within the ecosystem, including hardware wallet manufacturer Foundation and bitcoin publication Citadel21, publicly acknowledged sustaining financial losses as a direct consequence of the unauthorized transactions.
Investigation and Collaborative Tracking
In response to the exploit, BTCPay Server management initiated extensive coordination across multiple sectors of the digital asset industry. Public disclosures indicate that the project enlisted centralized cryptocurrency exchanges, specialized blockchain analytics companies, and law enforcement agencies to assist in tracking the illicit movement of funds across various networks. Affected merchants experiencing balance reductions were strongly advised to file formal incident reports with local police departments and any digital asset platforms where stolen tokens could potentially be deposited.
The bounty administration framework outlines that if multiple distinct intelligence reports contribute collaboratively to a successful recovery outcome, the distributed reward will be proportioned among the reporting victims. The calculation of these individual distributions relies strictly on the magnitude of the respective financial losses sustained by each victim alongside the measurable utility of the information provided. Secure reporting channels have been established through dedicated communication endpoints to safeguard sensitive disclosures throughout the recovery process.
Vulnerability Discovery and AI Code Scanning
The critical software flaw that enabled the security breach was originally identified by security researchers affiliated with the volunteer collective known as the Bitcoin Red Team. This independent group has recently deployed artificial intelligence tools to scan a wide array of bitcoin-related codebases, generating thousands of potential security findings across hundreds of distinct software projects. The specific vulnerability exploited in this incident was patched following a disclosure originating from this automated auditing approach.
As a gesture of recognition for the responsible disclosure, BTCPay Server announced direct donations to the researchers involved in locating the weakness. Developer Craig Raw and the Bitcoin Red Team fund each received 0.21 BTC as compensation for their proactive security work. The project emphasized that navigating modern digital infrastructure security requires acknowledging external contributions, particularly given the accelerating velocity of threats driven by automated analysis tools.
Risk Implications for Merchant Hot Wallets
The incident highlights ongoing architectural risks inherent in operating online payment servers and maintaining hot wallet liquidity for commercial transactions. Because merchant infrastructure often requires constant connectivity to facilitate rapid payment processing, the exposure surface for credential theft or remote code execution remains elevated compared to static archival storage. The compromise of LND credentials illustrates how a single point of administrative failure can cascade across multiple connected merchants, leading to immediate capital depletion.
Industry observers note that digital asset platforms facilitating commerce must rigorously partition operational funds from long-term reserves to mitigate systemic contagion. When payment processing nodes house significant transaction liquidity without robust isolation layers, attackers who breach administrative parameters gain unhindered access to connected commercial balances. This structural vulnerability necessitates a fundamental reevaluation of how hot wallet architectures are secured against sophisticated credential harvesting campaigns.
Defensive Recommendations and Cold Storage Shift
In the wake of the exploit, BTCPay Server issued urgent operational guidance to all participating merchants and node operators, strongly recommending the immediate transition of excess capital into secure cold storage environments. Merchants were advised to minimize the amount of liquidity held within active hot wallets, restricting active balances solely to immediate operational requirements. This defensive posture is designed to insulate merchants from potential secondary attacks while the broader ecosystem addresses lingering vulnerabilities.
Furthermore, security analysts suggest implementing multi-factor authentication, rigorous access control lists, and regular credential rotation schedules for all administrative interfaces connected to payment servers. As the threat landscape evolves with the integration of AI-driven attack vectors, payment infrastructure operators must adopt a zero-trust security paradigm. Regular third-party code audits and continuous monitoring of node logs remain essential components of an effective merchant defense strategy.
Conclusion, Reported Facts, and Unconfirmed Elements
In summary, CoinDesk reported that BTCPay Server established a recovery bounty up to 3 BTC following an exploit that drained merchant Lightning wallets through compromised LND credentials. Affected entities include Foundation and Citadel21, while the Bitcoin Red Team and developer Craig Raw received donations for disclosing the underlying vulnerability. These disclosures, however, remain not officially confirmed by independent law enforcement or regulatory authorities.
Moving forward, affected users and merchants must immediately audit node access controls, restrict hot wallet liquidity, and report losses to appropriate investigative authorities. Operators relying on BTCPay Server infrastructure should verify software patches and maintain cold storage protocols until the investigation concludes.
Cexvia conclusion
Incident Status and Next Operational Steps
CoinDesk reported that BTCPay Server announced a recovery bounty of 10% up to 3 BTC following an exploit that drained merchant Lightning wallets via compromised LND credentials, though these details remain not officially confirmed by regulatory or judicial authorities.
- Risk meaning
- The incident highlights operational and credential vulnerabilities in merchant-facing lightning infrastructure and payment servers.
- User action
- Merchant operators using Lightning infrastructure should immediately audit node credentials and migrate excess balances to cold storage.

