Telegram Live Chat

BTCPay Server Posts $190,000 Bounty After Lightning Node Exploit Drains Merchant Wallets
Home Crypto InvestmentBTCPay Server Posts $190,000 Bounty After Lightning Node Exploit Drains Merchant Wallets

BTCPay Server Posts $190,000 Bounty After Lightning Node Exploit Drains Merchant Wallets

by admin
0 comments

BTCPay Server is dangling up to $190,000 for anyone who can help recover bitcoin stolen in a recent exploit. Anyone. Including, apparently, whoever took it.

The open-source payment processor confirmed the breach and said it’s offering a bounty equal to 10% of whatever funds get recovered, capped at 3 BTC — worth roughly $190,000 at current bitcoin prices. The offer is open to any person with useful information, and BTCPay Server said it will split the bounty among multiple contributors if more than one person comes forward with actionable tips. Victims, per the project, will receive compensation proportional to their individual losses. BTCPay Server also made clear it has set up secure communication channels for anyone who wants to come forward quietly — which seems like a pretty direct nod to the attacker themselves.

Not just a bounty, though.

How the Exploit Actually Worked

The attackers got in by exploiting a vulnerability that let them grab credentials for LND — Lightning Network Daemon, the widely-used software that merchants run to operate a Lightning node. Once they had those credentials, draining the associated wallets was basically the next step. Fast and hard to stop once it’s in motion.

Among the confirmed victims: Foundation, the hardware wallet manufacturer, and Citadel21, a bitcoin-focused publication. Neither has said publicly how much they lost. BTCPay Server hasn’t disclosed a total figure for stolen funds either, which means the full scale of the damage is still murky. What’s clear is that the breach hit real, recognizable names in the bitcoin ecosystem — not just anonymous small merchants.

BTCPay Server said exchanges, blockchain analytics firms, and law enforcement are all now involved in tracing the stolen bitcoin. Affected merchants are being urged to file reports with local police and with any financial services that might have visibility into where the funds moved. The project seems to be running a parallel track — bounty on one side, law enforcement coordination on the other.

Two researchers got rewarded for doing the right thing. Developer Craig Raw and the Bitcoin Red Team each received a donation of 0.21 BTC from BTCPay Server for responsibly disclosing the vulnerability before things got worse. That’s the carrot for white-hat behavior. The bounty is the carrot for whoever might know where the stolen funds ended up.

Bitcoin Red Team’s Role and the AI Security Push

The Bitcoin Red Team is a volunteer group. No corporate backing, no big budget. Their focus is pointing AI models at bitcoin codebases to find weaknesses before bad actors do. They were instrumental in identifying the flaw that made this exploit possible, and their work has apparently turned up findings across multiple projects — not just BTCPay Server.

It’s worth sitting with that for a second. A volunteer group using AI-assisted code review caught a vulnerability that, once exploited, led to a six-figure theft affecting named companies. That’s probably not the last time we’ll see that dynamic play out. The Bitcoin Red Team’s approach — community-driven, AI-assisted, no formal employer — is kind of the scrappy answer to a security problem that the industry hasn’t fully solved with traditional methods.

BTCPay Server, for its part, is now pushing merchants hard on cold storage. The advice isn’t new, but the breach makes it feel more urgent: keep funds in cold storage, move excess money out of hot wallets regularly, don’t sit on large balances in internet-connected wallets. Especially now, the project said, as AI-driven technological change is moving fast and creating new attack surfaces alongside new defensive tools.

Hot wallets are convenient. They’re also, pretty much by definition, exposed. The LND exploit is a reminder that convenience in bitcoin infrastructure carries real financial risk — and that the gap between “good enough” security and “actually secure” can cost merchants everything sitting in those wallets.

What Merchants Should Do Right Now

BTCPay Server’s guidance is direct: report the theft to local authorities if you were affected. Contact any exchange or blockchain analytics service that might be able to flag or freeze the funds. And restructure how you hold bitcoin going forward — cold storage isn’t optional anymore, it’s the baseline.

The project didn’t give a timeline for the bounty or say how long the offer stays open. No details on that yet. What’s clear is that BTCPay Server is trying to run every recovery angle simultaneously — financial incentives, law enforcement, community disclosure, and security reform all at once.

Craig Raw and the Bitcoin Red Team got 0.21 BTC each. Foundation and Citadel21 still haven’t said what they lost.

Frequently Asked Questions

What is BTCPay Server offering as a bounty for the stolen bitcoin?

BTCPay Server is offering 10% of any recovered funds, up to a maximum of 3 BTC — approximately $190,000 at current bitcoin prices — split among anyone who provides useful information leading to recovery.

Who were the known victims of the BTCPay Server exploit?

Hardware wallet maker Foundation and bitcoin publication Citadel21 are among the confirmed victims, though neither has publicly disclosed the total amount of bitcoin they lost.

How did the attackers carry out the exploit?

Attackers exploited a vulnerability to steal credentials for LND, a popular Lightning node software, then drained the wallets connected to those compromised credentials.