Bitcoin holds near $64,000 as BTCPay backers pledge 3 BTC exploit bounty
The lack of enthusiasm means that traders likely view the event as a threat to merchants and Lightning users but not to Bitcoin. The market value of Bitcoin was estimated to be $1.28 trillion, and it had experienced a drop of approximately half a percent according to CoinMarketCap. The hack influenced software built on top of Bitcoin rather than the network itself.
Prices held while some Lightning nodes drained
However, BTCPay did not provide the total amount of loss or the number of affected nodes.
The project said its own onchain wallets, including hot wallets, were not affected. Instead, attackers could obtain LND administrator macaroon credentials from vulnerable BTCPay instances and use them to control connected Lightning wallets.
Backers put up 10% of anything recovered
The BTCPay Server Foundation is also donating 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the vulnerability. Raw, the developer of Sparrow Wallet, said he was among those affected.
What the macaroon flaw lets attackers do
All BTCPay Server versions before 2.4.2, including release candidates for that version, were vulnerable to the LND credential risk. BTCPay has not publicly assigned a CVE identifier to the incident.
The macaroon is a type of authentication credential used by LND to authorize API access. The vulnerabilities allowed malicious users to obtain the LND administrator macaroon from an impacted server, giving them control over the linked Lightning node and wallets.
The mechanism to update should be accessed through the Admin Dashboard → Server → Maintenance → Update, where the operators will be able to check if the footer reads 2.4.2. If they are unable to conduct the update right away, BTCPay suggests turning off the server.
Merely applying the patches may not be sufficient. Operators must refresh their Lightning credentials and macaroons since already stolen credentials may still be valid. Per the LND documentation, deletion of the macaroon files does not render the previously issued credentials invalid – the macaroon database must also be replaced.
Version 2.4.2 also addressed a separate TOTP two-factor authentication bypass via Greenfield Basic Authentication that was reported on August 4. However, this situation is unrelated to the LND flaw currently being exploited.
Why the surrounding software is the soft spot
This incident is mainly an infrastructure issue since the defect in question relates to the application layer of BTCPay, rather than to the consensus rules or cryptography that Bitcoin relies on. As a result, the Bitcoin network continued to operate without any issues.
A sizeable footprint still exists. BuiltWith specifies that 248 websites have used BTCPay Server at various times, including 74 currently operational websites, though such measurements do not include private installations.
Meanwhile, 1ML has reported there are about 5,585 active Lightning nodes at the moment, and the total amount of BTC available in them is approximately 2,640 BTC. River claims that Bitcoin adoption by merchants has increased by 74% in 2025, with the monthly transactions made in the Lightning Network reaching over $1 billion.
AI on both sides of the exploit
That concern extends beyond payment software. The recent Coldcard breach drained roughly 1,816 BTC from more than 5,200 addresses, with the fallout extending beyond the stolen funds as the company temporarily changed its data-retention practices.
Chainalysis has also warned that AI-assisted analysis and easier smart-contract decompilation could make attacks against poorly scrutinized code easier to scale.
For Bitcoin infrastructure, the lesson is broader than any single bug: AI can accelerate vulnerability discovery, but successful attacks can have consequences far beyond compromised code, from drained wallets and disrupted payments to investigations and changes in how companies handle customer data.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like

Apple (AAPL.US) All-Glass 20th Anniversary iPhone "Rashomon": Jefferies just said it was canceled, insiders quickly refute and say it is still proceeding as planned
It is reported that Apple's 20th anniversary edition iPhone, featuring glass as the core material, is still scheduled to be released in 2027.

ETH Continues to Respect Its Long-Term Macro Fractal, Looks at $10,000 – $16,000 as ATH Targets

