Latest News

BTCPay Supporters Pledge Up to 3 BTC to Help Recover Stolen…

How Did The BTCPay Vulnerability Expose Lightning Wallets?

Supporters of BTCPay Server have committed to funding a recovery bounty after a critical vulnerability allowed attackers to obtain administrator credentials for connected Lightning Network wallets and nodes.

The bounty will equal 10% of any stolen funds successfully recovered, capped at 3 BTC if all affected funds are returned. BTCPay has not disclosed the total amount stolen or the number of users affected, leaving the full financial impact of the incident unclear.

BTCPay Server disclosed on Friday that the vulnerability was being actively exploited and urged users to upgrade immediately to version 2.4.2. All versions before 2.4.2, including release candidates for that version, were vulnerable.

“The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project said.

An LND admin macaroon acts as a high-level authentication credential for a Lightning node. If an attacker obtains it, the credential can provide extensive control over the connected node and wallet, including the ability to move funds.

Several users, including Foundation and Citadel21, reported that their Lightning nodes had been drained. Sparrow Wallet developer Craig Raw, who helped discover the vulnerability, also said he was affected.

Which BTCPay Users Were At Risk?

The vulnerability specifically affected users running BTCPay Server with LND, one of the main implementations of the Bitcoin Lightning Network. Users relying on other Lightning implementations, or those not using Lightning at all, were not exposed to the same credential theft risk.

BTCPay nevertheless encouraged all users to install the latest version. The official 2.4.2 release closed the vulnerability.

BTCPay said its onchain Bitcoin wallets were not affected, including hot wallets managed through the platform. The distinction limits the scope of the exploit because attackers were able to target connected LND wallets rather than BTCPay’s broader onchain wallet infrastructure.

The incident illustrates the different security assumptions surrounding Bitcoin payment infrastructure. A merchant may use BTCPay to process both onchain and Lightning payments, but a weakness involving Lightning authentication credentials can expose one part of that setup while leaving the other unaffected.

Investor Takeaway

The BTCPay exploit shows that Bitcoin infrastructure risk can extend beyond private keys. Administrative credentials connected to Lightning nodes can provide attackers with broad wallet access, making software updates and credential security critical for payment operators.

How Is BTCPay Responding To The Security Failure?

The BTCPay Server Foundation is donating 0.21 BTC each to Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the vulnerability.

The Bitcoin Red Team is a volunteer security research group whose members include Rob Hamilton, Calle and Evan Kaloudis. BTCPay said a fuller postmortem is being prepared and that the project is adding stronger code-scanning and review processes with help from several external organizations.

The recovery bounty adds another incentive for stolen funds to be returned. Under the arrangement, recovery efforts can receive 10% of the amount recovered, with the total reward limited to 3 BTC in the event of a complete recovery.

Because BTCPay is open-source software, its code can be reviewed by both defenders and attackers. That transparency can help researchers discover weaknesses before they are exploited, but it also gives attackers an opportunity to inspect older code and search for security failures that may have remained unnoticed.

Is AI Making Crypto Exploits Easier To Find?

BTCPay said artificial intelligence may be changing the economics of software vulnerability discovery by making it faster and cheaper to review large codebases.

“AI is changing the balance between attackers and defenders. As models improve, it becomes faster and cheaper to inspect large codebases and find weaknesses,” BTCPay said. “Bitcoin projects are particularly exposed because they are valuable targets. The rest of the software industry will face the same reality.”

The warning follows another major security incident involving Coldcard hardware wallets, where at least $116 million in confirmed losses have been reported. Coldcard developer Coinkite said it believed an attacker may have used AI to review older public firmware and uncover the vulnerability.

Blockchain analytics firm Chainalysis separately estimated that $36.7 million was stolen from unverified, closed-source smart contracts during the first six months of 2026 through attacks involving decompiled bytecode, activity that may also have relied on AI-assisted analysis.

The same tools can strengthen defensive security by helping developers review code and identify weaknesses earlier. For Bitcoin and crypto projects holding valuable assets, however, the immediate problem is that attackers can use those capabilities at the same time, increasing pressure on developers to shorten the gap between vulnerability discovery and patch deployment.

You may also like