Cryptelio

BTCPay Server Addresses Vulnerability with 0.42 BTC Donation and Bounty for Stolen Funds

Cryptelio Editorial Published 10 Aug 2026 · 20:31 UTC
BTCPay Server Addresses Vulnerability with 0.42 BTC Donation and Bounty for Stolen Funds

BTCPay Server, the open-source Bitcoin payment processor, recently revealed a serious vulnerability that enabled attackers to remotely hijack Lightning Network nodes, resulting in fund thefts. The issue has been patched in version 2.4.2, and the project has donated 0.42 BTC to the researchers who reported the flaw.

The vulnerability affected BTCPay Server deployments utilizing LND Lightning nodes, with attackers exploiting exposed .macaroon credential files, which control access to these nodes. This flaw allowed unauthorized users to gain full control over a victim’s Lightning node without needing any login credentials.

Reports indicate that thefts were occurring before the patch was released, though the total amount stolen remains undisclosed. BTCPay Server's communications initially avoided technical specifics to prevent further exploitation while users updated their systems.

Craig Raw, the developer behind Sparrow Wallet, alongside members of the Bitcoin Red Team, was credited for the responsible disclosure of the vulnerability. In recognition of their efforts, BTCPay Server awarded them a donation of 0.42 BTC.

In addition to the donation, BTCPay Server announced a bounty program aimed at recovering stolen funds, offering up to three Bitcoins for actionable information leading to recovery. The project has reached out to affected users, urging them to update to the latest software version and review their node activity logs for any signs of unauthorized access.

BTCPay Server expressed its commitment to learning from this incident and improving security measures to protect its users in the future.

FAQ

What vulnerability was recently discovered in BTCPay Server?

A vulnerability was found that allowed attackers to remotely hijack Lightning Network nodes, leading to the theft of funds from BTCPay Server deployments using LND Lightning nodes.

How was the vulnerability exploited?

Attackers exploited exposed .macaroon credential files, which control access to Lightning nodes, allowing them to gain full control without needing login credentials.

What actions has BTCPay Server taken in response to this vulnerability?

BTCPay Server released a patch in version 2.4.2, donated 0.42 BTC to the researchers who reported the flaw, and launched a bounty program offering up to three Bitcoins for information leading to the recovery of stolen funds.

What should affected users do after the vulnerability disclosure?

Affected users are urged to update to the latest software version and review their node activity logs for any signs of unauthorized access.

Who was credited for the responsible disclosure of the vulnerability?

Craig Raw, the developer behind Sparrow Wallet, along with members of the Bitcoin Red Team, were credited for responsibly disclosing the vulnerability to BTCPay Server.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha