Supporters of BTCPay Server have offered a recovery bounty equal to 10% of any funds returned following an actively exploited vulnerability affecting the project’s LND integrations, with the reward capped at 3 BTC if all stolen funds are recovered.
The bounty was announced after BTCPay disclosed that versions released before 2.4.2, including 2.4.2 release candidates, contained a critical flaw that could expose LND admin macaroons. Those credentials grant extensive control over an LND Lightning node and its connected wallet, allowing an attacker who obtains them to access funds held on the affected Lightning setup.
BTCPay Server said the vulnerability has been fixed in the official 2.4.2 release and urged affected operators to update immediately. The project said its onchain wallets, including hot wallets, were outside the scope of the vulnerability, narrowing the incident to installations using LND through BTCPay Server.
The disclosure illustrates the distinct operational risks of Lightning infrastructure. A wallet’s bitcoin may remain secure at the base-chain level, yet node operators can face losses if software running on an internet-connected host exposes administrative credentials. For merchants and payment processors using Lightning liquidity, that can turn a server-side security issue into a direct loss of spendable funds.
lnd users face the immediate upgrade requirement
BTCPay Server said only instances using LND need version 2.4.2 specifically to address the macaroon exposure. Operators using other Lightning implementations, as well as BTCPay users who do not use Lightning, were not exposed to the LND credential risk described by the project. BTCPay nevertheless encouraged all users to install the latest release.
LND macaroons are authentication tokens used by the Lightning implementation to authorize actions. An admin macaroon can permit sensitive functions such as accessing wallet information, creating transactions, and operating the node. BTCPay said the vulnerability enabled attackers to obtain those credentials from affected server instances.
The project did not disclose how many installations were compromised or the aggregate amount taken. Foundation and Citadel21, two Bitcoin-focused organizations, reported that their Lightning nodes had been drained. Craig Raw, the developer of Sparrow Wallet, said he was also affected.
The absence of a published total makes the proposed recovery bounty difficult to value in dollar terms, but its structure offers a direct incentive for anyone able to identify, contact, or pressure the parties holding stolen Lightning funds. A 10% share can be substantial when funds are recoverable, while the 3 BTC ceiling limits the backers’ exposure if the total losses prove larger.
BTCPay Server did not say how the bounty will be administered or whether recovered funds must meet specific tracing or verification conditions. Its announcement focused on the percentage reward and the maximum payment available if all stolen funds are returned.
security researchers receive 0.42 btc in donations
The BTCPay Server Foundation said it will donate 0.21 BTC to Raw and another 0.21 BTC to the Bitcoin Red Team fund for finding and privately reporting the flaw. The project described the Bitcoin Red Team as a volunteer security-research group whose members include Rob Hamilton, Calle, and Evan Kaloudis.
Private reporting can give open-source projects time to patch dangerous vulnerabilities before technical details become widely available. In this case, BTCPay’s disclosure said the issue was already being actively exploited, placing urgency on the rollout of the fixed release.
BTCPay Server said it is preparing a postmortem and plans to strengthen its code-scanning and review processes with support from external organizations. The eventual report may clarify the attack path, the affected configurations, and whether operators could identify compromise through server logs or changes in Lightning wallet balances.
For affected node operators, upgrading stops the known vulnerability but does not automatically reverse an earlier credential theft. Administrators who suspect compromise may need to review node activity, replace exposed credentials, and assess whether any Lightning channels or wallet balances were moved without authorization. The appropriate recovery steps can vary depending on an operator’s LND configuration and its hosting environment.
exploits increasingly target exposed software and credentials
The BTCPay incident arrives amid a series of security events involving cryptocurrency software, hardware, and smart contracts. Coinkite, the company behind Coldcard hardware wallets, said an exploit tied to Coldcard devices had resulted in at least $116 million in confirmed losses. The company said older public firmware versions may have been reviewed with artificial intelligence to identify the issue.
Chainalysis estimated that attackers stole $36.7 million from unverified, closed-source smart contracts during the first six months of 2026 by decompiling contract bytecode. The figure points to a recurring problem: code does not need to be publicly published for attackers to study its behavior. Once deployed, smart-contract bytecode can often be inspected and analyzed for weaknesses.
CertiK said users lost more than $3.35 billion across 630 distinct hacks in 2025. The figures cover a wider range of attacks than the BTCPay flaw, but they underline how credential management, patching speed, and software review remain central to cryptocurrency security even as custody tools become more specialized.
The BTCPay case is particularly relevant to self-hosted payment infrastructure because the vulnerable component was a live service connected to a Lightning wallet. Operators often run such systems continuously to receive payments, which can create a narrow window between public disclosure of a bug and automated attempts to find unpatched deployments.
operators should focus on exposed services first
The immediate action for BTCPay Server operators using LND is to install version 2.4.2 and examine whether their instances were exposed before the patch. Keeping software current is most effective when paired with basic operational controls: limiting public access to administrative services, monitoring authentication and system logs, and separating funds needed for day-to-day Lightning payments from larger reserves.
The incident also offers a practical distinction for users choosing wallet infrastructure. Onchain wallet security and Lightning-node security can involve different attack surfaces even when both are managed through the same application. BTCPay Server said its onchain and hot wallets were unaffected, while LND-connected Lightning wallets faced the credential-exposure risk.
As BTCPay prepares its postmortem, the recovery bounty creates an unusual second track alongside the software fix: an effort to retrieve funds that may already have left affected nodes. Whether that effort succeeds will depend on the scale of the thefts, the movement of the funds, and the willingness of whoever controls them to return the bitcoin.
Learn how exchanges protect users from hacks and recoveries in this detailed guide on post-breach response.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

