BTCPay Server Offers Bitcoin Bounty for Recovery of Funds Stolen in Wallet Exploit
Key Takeaways
- •BTCPay Server is offering a bounty of 10% of recovered funds, capped at 3 BTC or roughly $190,000, for information that leads to the return of stolen Bitcoin, and the offer extends to the attacker themselves.
- •The exploit allowed attackers to obtain LND admin macaroons, which are authentication credentials that grant broad control over Lightning Network nodes and access to connected wallets.
- •The BTCPay Server Foundation will donate 0.21 BTC each to security researcher Craig Raw, creator of Sparrow Wallet, and the Bitcoin Red Team fund for responsibly disclosing the vulnerability.
- •BTCPay has not disclosed the total amount of Bitcoin stolen, the number of affected users, or whether any funds have been recovered so far.
- •The organization plans to strengthen code review processes and prioritize security patches over new feature development, citing the increasing risk of AI-assisted attacks on Bitcoin software.

BTCPay Server supporters are offering a bounty of 10% of any recovered funds, capped at 3 BTC (approximately $190,000), in exchange for information that leads to the return of Bitcoin stolen through a recent exploit. The offer is open to anyone, including the attacker responsible.
BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor used by merchants and Bitcoin advocates as an alternative to centralized payment platforms. Unlike custodial services, it allows users to operate their own nodes and control their own keys, a design philosophy that makes security vulnerabilities especially consequential for operators.
In a post on X on Monday, BTCPay announced the reward initiative. "We will examine our mistakes, but regret alone will not help affected users or secure the project," the organization wrote. "There is no time to waste. We have to learn, improve, and act quickly." (X post)
BTCPay first issued a warning about the attacks on Friday, advising users to update to version 2.4.2 immediately or take their servers offline. At that point, the project had not yet confirmed any thefts or disclosed the mechanism behind the exploit.
According to BTCPay, the vulnerability allowed attackers to obtain LND admin macaroons—authentication credentials that grant broad control over a Lightning Network node—which could then be used to access connected wallets. The Lightning Network is a layer-2 payment protocol built on the Bitcoin blockchain designed to enable faster and cheaper transactions by routing payments through channels between users. LND, or Lightning Network Daemon, is one of the most widely used Lightning node implementations, meaning the attack surface exposed by this vulnerability is relevant to a broad segment of Lightning infrastructure operators.
The project has not disclosed the total amount of Bitcoin stolen, the number of affected users, or whether any funds have been recovered so far.
If multiple tips contribute to fund recovery, the bounty will be divided in coordination with victims. BTCPay stated it would weigh each victim's losses, the total amount recovered, and the relative usefulness of each tip when allocating the reward.
Separately, the BTCPay Server Foundation will donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for responsibly disclosing the vulnerability. Craig Raw is the creator of Sparrow Wallet, a popular open-source Bitcoin desktop wallet.
"These are modest contributions, but they are what we can offer as a FOSS project and a way to appreciate people doing critical security work, which helps the entire ecosystem," BTCPay wrote.
Looking ahead, the organization said it is strengthening code review processes and prioritizing security patches over new feature development, citing the growing risk that AI tools make it easier for attackers to identify vulnerabilities in Bitcoin software. The incident highlights a broader tension in the open-source Bitcoin ecosystem, where volunteer-driven projects maintain critical payment infrastructure with limited resources compared to their commercial counterparts.
"Defending software in this environment requires better tools, more thorough reviews, faster security responses, and support for researchers who find and responsibly report vulnerabilities," BTCPay wrote.