BTCPay Server’s $190,000 Bounty: Lightning Exploit Spurs Community Hunt

Stylized Bitcoin coin with golden rim light amid glowing network filaments and smoky, moody blue-grey backdrop

Bounty Hunt Begins After Wallet Drain

BTCPay Server, a widely used open-source bitcoin payment processor, is offering a recovery bounty of up to 3 BTC—worth about $190,000 at current prices—after attackers exploited a critical vulnerability and drained merchant wallets last week. The incident targeted Lightning Network nodes integrated with BTCPay, allowing hackers to steal credentials and sweep funds from affected wallets. The precise amount lost remains uncertain, as neither BTCPay nor impacted users have released an official tally. However, the scale of the response underscores the seriousness of the breach.

On paper, BTCPay Server’s core on-chain wallets were not compromised, but Lightning Network wallets connected via LND (Lightning Network Daemon) were left exposed. Foundation, maker of the Passport hardware wallet, confirmed its Lightning node was drained in the attack, though its on-chain hot wallet was untouched. Citadel21, a bitcoin-focused publication, also reported its node held little but was swept by the attackers.


Every BTCPay Server version before 2.4.2 was vulnerable to the exploit disclosed last week.

The vulnerability affected every BTCPay Server version before 2.4.2 and allowed unauthenticated remote attackers to retrieve credential files remotely—a critical flaw that let them take control of nodes and move funds without detection.

Attackers, Allies Both Eligible for Reward

In an unusual move reflecting both urgency and pragmatism, BTCPay Server’s supporters have committed to funding a bounty for information or direct recovery of stolen funds. The offer is open not only to white-hat hackers and community members but also to the attacker themselves. Anyone able to facilitate the return of stolen coins can claim 10% of what is recovered, up to 3 BTC. Communication is available through a dedicated security address and encrypted channels like Signal.

No official loss figure has been published so far.

The bounty comes as exchanges, blockchain analytics firms, and law enforcement agencies mobilize to help trace the stolen coins. BTCPay Server has urged affected users to share on-chain addresses and transaction details and to file reports with local authorities or relevant exchanges—steps that could help track or freeze funds if they touch regulated platforms.

Security Whistleblowers Earn Bitcoin Thanks

Responsible disclosure played a pivotal role in containing the fallout from this exploit. Developer Craig Raw and the Bitcoin Red Team are each set to receive 0.21 BTC from BTCPay Server as thanks for their role in identifying and reporting the vulnerability before it could be more widely abused. That’s over $13,000 in rewards at current prices—a concrete signal that security contributions are valued by the project’s leadership.

The Bitcoin Red Team had recently begun using AI models to review bitcoin codebases for vulnerabilities and filed thousands of findings across hundreds of projects. Their efforts led directly to the report that prompted this urgent patching effort. According to coindesk.com, their early warning likely prevented even greater losses by giving maintainers time to act before mass exploitation occurred.

BTCPay Server published technical details and remediation guidance alongside their bounty announcement; users running LND were urged to update immediately and rotate credentials since previously stolen credentials would remain valid even after patching.

AI Joins Both Sides of the Exploit Race

There’s a new wrinkle in this incident: AI may have played a part on both sides of the breach. While the Bitcoin Red Team leveraged AI tools for code review and security analysis—uncovering thousands of issues including this critical flaw—BTCPay noted that attackers may also have used AI-driven techniques to identify or exploit vulnerabilities faster than traditional methods allow.

This incident comes just days after another high-profile security lapse involving Coldcard firmware led to over $100 million in confirmed losses across multiple projects—a stark reminder that even established tools can harbor hidden flaws with devastating consequences.

BTCUSD : Technical signal

For now, all eyes remain on whether any portion of the stolen bitcoin will be recovered—and if so, how much will flow back into merchant hands versus into those of whoever cracks the case first.

Summary Points

  • BTCPay Server is offering a recovery bounty of up to 3 BTC (about $190,000) for stolen funds after last week's exploit.
  • The vulnerability affected all BTCPay Server versions before 2.4.2, allowing attackers to steal Lightning Network credentials and drain wallets.
  • BTCPay Server will donate 0.21 BTC each to Craig Raw and the Bitcoin Red Team for responsible disclosure of the vulnerability.

What remains under scrutiny

If any portion of the stolen funds is returned and verified, BTCPay Server will pay a recovery bounty of 10% up to a maximum of 3 BTC (about $190,000), but the total amount lost has not yet been published by either BTCPay or affected victims.