OKX Banner
BTC $64,211.00 (-1.70%)
ETH $1,879.06 (-2.50%)
BNB $606.32 (+0.10%)
XRP $1.01 (-3.20%)
SOL $75.69 (-1.50%)
TRX $0.33 (+0.60%)
HYPE $55.29 (+0.70%)
DOGE $0.07 (+0.20%)
RAIN $0.01 (+2.00%)
LEO $9.40 (-1.70%)
ZEC $485.39 (-4.50%)
XMR $393.56 (+0.20%)
ADA $0.19 (-4.70%)
LINK $8.66 (+3.50%)
XLM $0.16 (-2.30%)
BCH $214.95 (-0.90%)
CC $0.09 (-3.90%)
GRAM $1.34 (-0.50%)
LTC $45.49 (-0.70%)
USDG $1.00 (+0.00%)

BTCPay Server Bug Drained Lightning Wallets, Offers 3 BTC Bounty for Recovery

Twitter icon  •  Published há 1 hora on August 11, 2026  •  Hassan Maishera

BTCPay Server supporters offered a recovery bounty after attackers exploited an LND vulnerability, while the project warned of AI-driven security risks.

BTCPay Server Bug Drained Lightning Wallets, Offers 3 BTC Bounty for Recovery

TL;DR

  • BTCPay Server supporters have offered a bounty equal to 10% of recovered funds, capped at 3 BTC for a full recovery.

  • The vulnerability exposed LND administrator credentials, allowing attackers to control connected Lightning wallets.

  • BTCPay Server fixed the flaw with version 2.4.2 and urged all users to update.

  • Onchain wallets were unaffected, but several users reported that their Lightning nodes had been drained.

Supporters of BTCPay Server have committed to funding a recovery bounty following the exploitation of a critical vulnerability in the open-source Bitcoin payment processor.

The bounty will equal 10% of any stolen funds successfully recovered, with the payment capped at 3 BTC if all affected funds are returned, according to an announcement published on Monday.

BTCPay Server first disclosed the active exploit on Friday and urged users to upgrade their software immediately to version 2.4.2.

According to a security advisory, every version released before 2.4.2—including release candidates for the update—was vulnerable.

Exploit Exposed LND Administrator Credentials

The vulnerability allowed attackers to obtain LND administrator macaroon credentials from affected BTCPay Server installations.

“The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project explained on X.

A Lightning macaroon is an authentication token used by Bitcoin Lightning nodes. Administrator-level macaroons can grant broad control over a connected wallet, including the ability to initiate transactions.

By stealing these credentials, attackers could gain full access to linked Lightning wallets and drain their funds.

Users running alternative Lightning implementations were not directly exposed to this particular LND credential risk. Those who did not use Lightning were also unaffected by the exploit.

However, BTCPay Server encouraged all users to install the latest version as a precaution.

BTCPay Server Version 2.4.2 Fixes Vulnerability

The official release of BTCPay Server 2.4.2 patched the security flaw.

The team clarified that the exploit did not affect BTCPay Server’s onchain Bitcoin wallets, including hot wallets. The vulnerability was limited to connected LND Lightning wallets whose administrator credentials could be exposed.

BTCPay has not disclosed how much Bitcoin was stolen or how many servers were compromised.

However, some users and organizations, including Foundation and Citadel21, publicly reported that their Lightning nodes had been drained.

The project said it was preparing a more detailed postmortem that would provide further information about the incident and its response.

The BTCPay Server Foundation will donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for identifying and privately disclosing the critical vulnerability.

Raw, the developer of Sparrow Wallet, also said he was affected by the exploit. The Bitcoin Red Team is a volunteer security-research collective whose members include Rob Hamilton, Calle and Evan Kaloudis. 

The group focuses on finding and responsibly disclosing vulnerabilities within the Bitcoin ecosystem.

BTCPay said it was also introducing more rigorous code-scanning and review procedures with assistance from several external organizations.

BTCPay Warns AI Is Changing Cybersecurity

BTCPay suggested that artificial intelligence may have played a role in discovering the vulnerability, highlighting the growing impact of AI on software security.

“AI is changing the balance between attackers and defenders,” BTCPay said. “As models improve, it becomes faster and cheaper to inspect large codebases and find weaknesses.”

The project warned that Bitcoin applications are particularly attractive targets because they often provide direct access to valuable digital assets. However, it added that similar risks will increasingly affect the wider software industry.

AI tools can accelerate legitimate security audits and help developers identify weaknesses. At the same time, attackers can use the same capabilities to search public codebases for previously overlooked flaws.

The BTCPay Server incident follows the major Coldcard exploit, which has reportedly caused at least $116 million in confirmed losses.

Coinkite, the company behind the Coldcard hardware wallet, said an attacker may have used AI to examine older publicly available firmware and uncover the vulnerability.

AI-assisted attacks may also extend beyond Bitcoin software. Chainalysis estimated that attackers stole approximately $36.7 million from unverified, closed-source smart contracts during the first half of 2026 by decompiling their bytecode—a process the firm suggested likely involved artificial intelligence.

Bitcoin security specialist Jameson Lopp has similarly argued that AI is making it easier both to discover software vulnerabilities and to conduct defensive security reviews.

The recent BTCPay and Coldcard incidents underline the growing pressure on cryptocurrency developers to improve code audits, vulnerability disclosure programs and security monitoring as AI lowers the cost of identifying exploitable weaknesses.

 

New Solana Vaults Use AI to Chase 15% Yields on SOL
Next article New Solana Vaults Use AI to Chase 15% Yields on SOL
Hassan Maishera

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.