BTCPay Backers Offer Bitcoin Bounty After Wallet Exploit
Supporters of BTCPay Server have committed to funding a recovery bounty after attackers exploited a critical vulnerability and stole Bitcoin from some users running LND-connected Lightning wallets. The bounty will equal 10% of recovered funds, with the total reward capped at 3 BTC.
BTCPay has not disclosed the total amount stolen or the number of users affected. The project said the vulnerability exposed LND administrator credentials, allowing attackers to access connected Lightning wallets and move funds.
Bounty Offers Up to 3 BTC for Recovery
BTCPay said the offer is open to anyone with actionable information that leads to recovering stolen funds, including the attacker. If several reports contribute to a recovery, the reward will be divided in coordination with victims based on factors including losses, recovered funds and the usefulness of the information provided. The project said:
“Friends and supporters of the BTCPay Server project have committed to funding a bounty to recover the stolen funds”.
Vulnerability Exposed LND Credentials
The security flaw affected every BTCPay Server version before 2.4.2, including release candidates for that version. An unauthenticated attacker could obtain .macaroon administrator credential files used by LND, allowing access to affected Lightning nodes and their funds.
BTCPay said its own on-chain wallets, including hot wallets, were not affected by the vulnerability. Funds held within an affected LND node could still be at risk, and operators using LND were told to upgrade immediately to BTCPay Server 2.4.2 and LND 0.21.1.
BTCPay Rewards Security Researchers
The BTCPay Server Foundation also said it will donate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund for responsibly identifying and reporting the vulnerability. The project is also working with exchanges, blockchain analytics companies and law enforcement agencies to trace stolen funds.
BTCPay said it is strengthening code scanning and external security reviews following the incident. It also plans to prioritize security patches and system hardening over major new features for the foreseeable future.