Supporters of BTCPay Server have offered a recovery bounty of up to 3 BTC after attackers exploited a critical vulnerability affecting versions earlier than 2.4.2. The issue exposed LND administrator macaroon credentials, allowing attackers to take control of connected Lightning wallets.

BTCPay said its on-chain wallets were not affected. The project urged users to upgrade to version 2.4.2 immediately or temporarily shut down affected servers and rotate exposed credentials.

Bug exposed Lightning node credentials

According to BTCPay Server, the flaw let attackers obtain LND admin macaroons from vulnerable deployments. With those credentials, an attacker could control the associated Lightning node and any connected Lightning wallet.

The problem applied to BTCPay Server releases before 2.4.2. BTCPay characterized the issue as serious and said exploitation was active, making rapid mitigation important for operators using affected versions.

Backers set recovery incentive

Backers of the project pledged a bounty equal to 10% of any recovered stolen funds. If the full amount is returned, the payout is capped at 3 BTC.

Separately, the BTCPay Server Foundation said it donated 0.21 BTC to security researcher Craig Raw and another 0.21 BTC to the Bitcoin Red Team fund. The donations were made in connection with the discovery and private reporting of the vulnerability.

Bitcoin network not directly affected

The incident was described as an infrastructure problem at the application layer rather than a weakness in Bitcoin itself. BTCPay’s warning focused on software connected to Lightning operations, not the underlying Bitcoin protocol.

That distinction mattered as the broader network continued to operate normally. Bitcoin traded near $64,000 during the episode, with the source article noting little immediate reaction in price.

What happens next

The immediate confirmed step for exposed operators is to move to BTCPay Server 2.4.2 or take affected servers offline until they can be secured. BTCPay also advised rotating credentials because the exploit centered on leaked LND administrator macaroons.

The source article noted that analysis of the vulnerability was still continuing. It also pointed to a broader security concern for open-source infrastructure: AI-assisted auditing may help defenders identify bugs faster, while also potentially reducing the effort needed for attackers to search codebases for weaknesses.

Source: Cryptopolitan