BTCPay Server donates 0.42 BTC for responsible vulnerability disclosure and offers bounty for stolen fund recovery
BTCPay Server, the open-source Bitcoin payment processor that lets merchants skip the middlemen, just disclosed a critical vulnerability that allowed attackers to remotely hijack Lightning Network nodes and drain funds. The project has patched the issue in version 2.4.2, donated 0.42 BTC to the security researchers who flagged the flaw, and announced a bounty program aimed at recovering stolen funds.
The vulnerability affected BTCPay Server deployments running LND Lightning nodes. And by the time the fix arrived, attackers had already started helping themselves.
What went wrong
The flaw centered on .macaroon credential files, which are essentially the authentication keys that control access to an LND Lightning node. In affected versions of BTCPay Server, these credential files were exposed to unauthenticated remote access. No login required. No special privileges needed. An attacker who knew where to look could grab the macaroon files and take full control of a victim’s Lightning node, opening the door to siphon funds from active payment channels.
On-chain Bitcoin wallets were not affected. The vulnerability was isolated to the Lightning integration layer. Confirmed reports indicate that thefts were already in motion before the patch dropped, though the total amount stolen has not been publicly disclosed. BTCPay Server’s initial communications deliberately omitted specific technical details to avoid giving attackers a roadmap while users scrambled to update.
The people who found it
Credit for the responsible disclosure goes to Craig Raw, the developer behind Sparrow Wallet, along with several members of the Bitcoin Red Team: Rob Hamilton, Calle, and Evan Kaloudis. Their work in identifying, analyzing, and privately reporting the vulnerability gave BTCPay Server the time it needed to develop and ship a fix before broadcasting the details publicly.
BTCPay Server recognized their contributions with a donation of 0.42 BTC. The project has also historically rewarded security researchers. Back in 2022, BTCPay Server issued a $5,000 bounty for a separate vulnerability disclosure.
Beyond the disclosure reward, BTCPay Server announced a bounty program specifically targeting the recovery of stolen funds.
What users need to do
The advisory is straightforward: update to BTCPay Server v2.4.2 and LND v0.21.1 immediately. Users who can’t update right away are advised to take their servers offline temporarily rather than leave them exposed.
BTCPay Server also recommended that anyone running an LND node review their node activity logs for signs of unauthorized access. If your macaroon files were compromised before the patch, updating the software alone won’t undo the damage. You’d need to rotate credentials and potentially close and reopen channels with fresh keys.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Value Aligned Research Advisors falls 44% amid AI stock declines
Top News Today: Stocks Fall as Oil Rally Spurs Inflation Fears
Worldcoin rebounds from $0.30 support, eyes $0.38 resistance for bullish confirmation
ICP crypto price jumps 8%: Can Caffeine AI and Mission 70 support a recovery?

