Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
BTCPay Server donates 0.42 BTC for responsible vulnerability disclosure and offers bounty for stolen fund recovery

BTCPay Server donates 0.42 BTC for responsible vulnerability disclosure and offers bounty for stolen fund recovery

CryptobriefingCryptobriefing2026/08/10 19:57
By:Cryptobriefing

BTCPay Server, the open-source Bitcoin payment processor that lets merchants skip the middlemen, just disclosed a critical vulnerability that allowed attackers to remotely hijack Lightning Network nodes and drain funds. The project has patched the issue in version 2.4.2, donated 0.42 BTC to the security researchers who flagged the flaw, and announced a bounty program aimed at recovering stolen funds.

The vulnerability affected BTCPay Server deployments running LND Lightning nodes. And by the time the fix arrived, attackers had already started helping themselves.

What went wrong

The flaw centered on .macaroon credential files, which are essentially the authentication keys that control access to an LND Lightning node. In affected versions of BTCPay Server, these credential files were exposed to unauthenticated remote access. No login required. No special privileges needed. An attacker who knew where to look could grab the macaroon files and take full control of a victim’s Lightning node, opening the door to siphon funds from active payment channels.

Advertisement
window.sevioads = window.sevioads || []; var sevioads_preferences = []; sevioads_preferences[0] = {}; sevioads_preferences[0].zone = "de1434f5-fa9e-44a6-93c3-4c2439763717"; sevioads_preferences[0].adType = "banner"; sevioads_preferences[0].inventoryId = "c5700508-581b-472c-8fdd-a931cdbfc8e1"; sevioads_preferences[0].accountId = "1e47efc1-ec2d-4fca-a8b9-354e249e5095"; sevioads.push(sevioads_preferences);

On-chain Bitcoin wallets were not affected. The vulnerability was isolated to the Lightning integration layer. Confirmed reports indicate that thefts were already in motion before the patch dropped, though the total amount stolen has not been publicly disclosed. BTCPay Server’s initial communications deliberately omitted specific technical details to avoid giving attackers a roadmap while users scrambled to update.

The people who found it

Credit for the responsible disclosure goes to Craig Raw, the developer behind Sparrow Wallet, along with several members of the Bitcoin Red Team: Rob Hamilton, Calle, and Evan Kaloudis. Their work in identifying, analyzing, and privately reporting the vulnerability gave BTCPay Server the time it needed to develop and ship a fix before broadcasting the details publicly.

BTCPay Server recognized their contributions with a donation of 0.42 BTC. The project has also historically rewarded security researchers. Back in 2022, BTCPay Server issued a $5,000 bounty for a separate vulnerability disclosure.

Beyond the disclosure reward, BTCPay Server announced a bounty program specifically targeting the recovery of stolen funds.

What users need to do

The advisory is straightforward: update to BTCPay Server v2.4.2 and LND v0.21.1 immediately. Users who can’t update right away are advised to take their servers offline temporarily rather than leave them exposed.

BTCPay Server also recommended that anyone running an LND node review their node activity logs for signs of unauthorized access. If your macaroon files were compromised before the patch, updating the software alone won’t undo the damage. You’d need to rotate credentials and potentially close and reopen channels with fresh keys.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Trump presses the Federal Reserve to "cut rates to save the economy," but the market is betting on a 60% probability of a rate hike in September

Ahead of the Federal Reserve’s September monetary policy meeting (scheduled for September 15-16), U.S. President Trump and senior administration officials have made intensive statements, urging the central bank not to raise interest rates and even calling for a cut in the benchmark rate.

智通财经2026/09/09 23:31
Trump presses the Federal Reserve to "cut rates to save the economy," but the market is betting on a 60% probability of a rate hike in September

US energy stocks remain "cheap" after surging: High oil prices may lead to a valuation recovery

The Energy Select Sector SPDR ETF, which tracks US energy stocks, has surged over 43% year-to-date, far outperforming other S&P 500 sectors. Despite this, the energy sector remains one of the lowest-valued sectors within the S&P 500. High oil prices have led to excess profits for energy stocks; although Wall Street previously viewed this round of earnings growth as a temporary phenomenon, if elevated oil prices persist longer than expected, the valuation recovery of energy stocks may have only just begun.

华尔街见闻2026/09/09 23:21

Besant brings Peashooter to tank battle, US Treasury repo hits a wall, 10-year US Treasury yield at three-year high

U.S. Treasury bonds are currently facing multiple pressures, including high oil prices intensifying inflation, rising expectations of Federal Reserve rate hikes, soaring fiscal deficits, and large-scale corporate bond issuances. At the same time, the $6 billion buyback scale has fallen short of market expectations. While Bessent had previously made lowering long-term yields a policy goal, on Tuesday he admitted that it's impossible to change the "equilibrium" price of government bonds. Analysts pointed out that buybacks cannot stop the fundamentals-driven yield trends, likening it to "the Treasury bringing a pea shooter to a tank battle."

华尔街见闻2026/09/09 23:01