BTCPay Server Vulnerability Drains Lightning Nodes, Prompting 3-BTC Recovery Bounty
The vulnerability, present in BTCPay versions prior to 2.4.2, allowed attackers to seize LND admin‑macaroon credentials from servers. With those credentials, the attackers gained full control over connected Lightning Network wallets.
The flaw was uncovered by the Bitcoin Red Team—a volunteer security group that includes Rob Hamilton, Calle, and Evan Kaloudis. After privately reporting the issue to BTCPay, the project confirmed the problem and released an emergency patch in version 2.4.2. BTCPay urged all users to upgrade immediately or take their servers offline.
Several affected users confirmed that their LN nodes had been drained. The Bitcoin Foundation and the bitcoin‑zine Citadel21 reported that their channels were force‑closed and funds were moved. Sparrow Wallet developer Craig Raw, who helped identify the flaw, also stated that his node was compromised.
The exploit targeted only instances using LND, one of the main Lightning implementations. Users running other LN software—or those who did not use LN at all—were not exposed to the same credential‑theft risk. BTCPay clarified that its on‑chain Bitcoin wallets, including hot wallets managed through the platform, were not affected.
In response, BTCPay supporters announced a recovery bounty: recoveries will earn 10 % of the amount successfully returned, capped at 3 BTC if all stolen funds are recovered. The bounty is intended to incentivize the return of drained funds.
BTCPay also pledged to donate 0.21 BTC each to Craig Raw and the Bitcoin Red Team fund for discovering and reporting the vulnerability.
To strengthen future defenses, BTCPay said it is adding more rigorous code‑scanning and review processes with help from several external organizations. The project noted that its open‑source nature allows both defenders and attackers to review the code, which can accelerate vulnerability discovery.
BTCPay highlighted that artificial intelligence is reshaping the economics of software vulnerability discovery. As AI models improve, inspecting large codebases becomes faster and cheaper, benefiting both attackers and defenders. The same trend appeared in other recent incidents: a Coldcard hardware‑wallet breach reportedly involved a $116 million loss, and developer Coinkite suggested that an attacker may have used AI to analyze older firmware. Chainalysis estimated that $36.7 million was stolen from closed‑source smart contracts in the first half of 2026 through attacks that may have relied on AI‑assisted analysis.
The BTCPay incident underscores the layered security assumptions in Bitcoin payment infrastructure. Merchants can use BTCPay to process both on‑chain and LN payments, but a weakness in LN authentication can expose one part of the system while leaving the other intact.
BTCPay’s response—prompt patching, a recovery bounty, and enhanced code‑review—illustrates the rapid cycle of vulnerability disclosure and remediation that has become standard in the crypto ecosystem.
All affected users are advised to upgrade to BTCPay Server 2.4.2 or disable the LN service until the patch is applied. BTCPay is monitoring the situation and will release a full post‑mortem once the investigation is complete.
The incident serves as a reminder that administrative credentials, such as LND admin macaroons, can provide attackers with broad wallet access. Maintaining up‑to‑date software and secure credential practices remains essential for operators of Bitcoin payment infrastructure.