Security Incident and Risk Intelligence
BTCPay Server Supporters Back 10% Bounty to Recover Stolen Bitcoin Following LND Exploit
According to reporting by crypto.news, BTCPay Server supporters have backed a recovery bounty equal to 10% of funds retrieved from a recent Lightning wallet exploit, with the reward capped at 3 BTC if all stolen assets are recovered. The incident exposed LND administrator credentials, though the total stolen amount is not officially confirmed.

Overview of the BTCPay Server Exploit and Recovery Bounty
According to reporting by crypto.news published on August 11, 2026, supporters of the open-source Bitcoin payment processor BTCPay Server have backed a recovery bounty program. The initiative offers a reward equal to 10% of any funds successfully retrieved from a recent Lightning wallet exploit. If all stolen assets are completely recovered, the reward is capped at a maximum of 3 BTC. The bounty was introduced as part of the broader project response to a critical security flaw that impacted vulnerable server installations across the global network.
Publisher crypto.news noted that the open-source payment processor has not officially disclosed the exact financial volume of cryptocurrency stolen or the precise number of servers compromised during the breach. However, several affected users and entities, including Citadel21 and Foundation, reported publicly that funds held within their connected Lightning nodes were rapidly drained. The ongoing nature of the incident has prompted heightened vigilance among self-hosted node operators relying on the software for transaction processing.
Technical Vulnerability Mechanism and Affected Versions
Publisher crypto.news reported that the vulnerability specifically affected all BTCPay Server releases prior to version 2.4.2, including release candidate builds of 2.4.2. The security flaw allowed an unauthorized attacker to obtain LND administrator macaroon credentials from exposed BTCPay instances. Once acquired, these credentials provided extensive administrative permissions over the associated wallet, granting malicious actors the ability to control and drain funds held through the compromised LND configuration.
The reporting clarified that the vulnerability was strictly limited to LND credentials and did not expose users running alternative Lightning implementations or operators who do not utilize Lightning functionality. Furthermore, BTCPay's native onchain wallets, including hot wallets maintained by software users, were confirmed not to have been compromised through this specific attack vector. This distinction restricted the known breach path exclusively to connected LND wallets rather than the broader portfolio of Bitcoin holdings managed via BTCPay.
Immediate Remediation and Official Response Measures
Following the discovery of the flaw, project maintainers released the final version 2.4.2 of BTCPay Server containing an explicit patch for the vulnerability. Operators running older installations were urgently advised by the project to update their servers immediately to prevent exploitation. In addition to releasing the software patch, the project has initiated the implementation of stronger code-scanning and review procedures with assistance from several external cybersecurity organizations to prevent future occurrences.
The organization is also preparing a comprehensive postmortem document intended to provide granular technical details regarding the vulnerability and the subsequent response timeline. This upcoming report is expected to shed light on how the security lapse occurred and outline the defensive enhancements being integrated into the codebase. Meanwhile, researchers who responsibly disclosed the flaw prior to public exploitation have been slated for financial rewards funded by the BTCPay Server Foundation.
Researcher Contributions and Bounty Allocations
Publisher crypto.news detailed that alongside the recovery bounty program, the BTCPay Server Foundation is issuing direct rewards to the independent researchers who originally identified and privately reported the vulnerability. Specifically, the foundation is donating 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund. Craig Raw discovered the security issue and privately notified the developers, enabling them to construct and test a fix before the vulnerability details leaked to the public.
The Bitcoin Red Team operates as a volunteer security research group consisting of members such as Rob Hamilton, Calle, and Evan Kaloudis, focusing on discovering and reporting vulnerabilities affecting Bitcoin-related software. These researcher rewards operate separately from the supporter-backed recovery bounty, which offers 10% of retrieved funds up to a 3 BTC ceiling. The dual-track incentive structure reflects ongoing efforts within the Bitcoin ecosystem to reward both proactive vulnerability discovery and post-incident asset recovery.
Artificial Intelligence Involvement and Broader Ecosystem Context
As part of its preliminary investigation, the BTCPay Server project raised the possibility that artificial intelligence tools may have been utilized to uncover the vulnerable code paths. The project noted that advancing AI models have significantly reduced the time and financial cost required to analyze large code repositories for weaknesses, altering the tactical capabilities accessible to both malicious attackers and independent security researchers. Bitcoin infrastructure remains an attractive target because flaws can yield direct access to digital assets.
This observation aligns with wider security trends reported across the cryptocurrency sector during 2026. Security firm CertiK previously noted substantial crypto losses and warned that AI-assisted attacks, malware targeting code repositories, and infrastructure weaknesses were emerging as prominent threat vectors. Similar concerns regarding AI-driven code inspection were previously raised following a major exploit involving Coldcard hardware wallets, which resulted in substantial financial losses and prompted widespread re-evaluation of open-source codebase security.
Assessment and Actionable Next Steps
According to reporting by crypto.news, BTCPay Server supporters have backed a 10% recovery bounty capped at 3 BTC to retrieve funds lost in an LND wallet exploit affecting older installations. While the exploit exposed administrator credentials and drained connected nodes, the total financial loss remains not officially confirmed by the project. The affected user group comprises operators of vulnerable BTCPay Server instances utilizing Lightning Network integrations.
What changes now is that the software patch version 2.4.2 is fully available, and enhanced code-scanning procedures are being rolled out. The next action for all server administrators is to immediately verify their software version, upgrade to version 2.4.2 or later without delay, and carefully audit all connected node permissions to prevent unauthorized access.
Cexvia conclusion
Investigation and Remediation Summary
According to reporting by crypto.news, an exploit targeting BTCPay Server exposed LND administrator credentials and drained connected Lightning nodes, prompting a 10% recovery bounty and version 2.4.2 patch. The exact financial loss and the total number of affected servers remain not officially confirmed.
- Risk meaning
- The security incident highlights ongoing infrastructure risks in self-hosted payment processors, where exposed administrator credentials can lead to direct fund drainage from connected node setups.
- User action
- Operators must immediately upgrade their BTCPay Server instances to version 2.4.2 or later and audit all connected Lightning network permissions.

