NewsCryptoBTCPay Server Offers 3 Bitcoin Bounty for Recovery of Stolen Funds Following Wallet Exploit

BTCPay Server Offers 3 Bitcoin Bounty for Recovery of Stolen Funds Following Wallet Exploit

Author: Bitcoin Magazine·

Key Takeaways

  • •BTCPay Server is offering a recovery bounty set at 10 percent of recovered funds, capped at a maximum of three bitcoins, to the attacker or anyone providing actionable information.
  • •Attackers exploited the vulnerability by extracting Lightning Network admin macaroon credentials from affected BTCPay Server instances, which allowed them to control Lightning nodes and move funds.
  • •The BTCPay Server Foundation donated 0.21 bitcoins each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund in recognition of their responsible disclosure of the vulnerability.
  • •The project is coordinating with exchanges, blockchain analytics firms, and law enforcement agencies to help track the stolen coins and is urging affected users to file reports and share transaction details.
  • •The project warned that improving AI models are making it faster and cheaper for adversaries to identify vulnerabilities in Bitcoin project codebases, shifting the advantage toward attackers.
BTCPay Server Offers 3 Bitcoin Bounty for Recovery of Stolen Funds Following Wallet Exploit

Supporters of BTCPay Server have committed to funding a bounty of up to three bitcoins for the recovery of funds stolen through a recently disclosed vulnerability in the open-source bitcoin payment processor, the project announced in a statement.

BTCPay Server is a self-hosted payment processor that enables merchants to accept Bitcoin payments without relying on third-party intermediaries, and the vulnerability underscores the challenges even non-custodial infrastructure faces when credential management is compromised.

The bounty is set at 10 percent of whatever is recovered, capped at three coins in the event of a full recovery. The project extended the offer directly to the attacker as well as to anyone else holding actionable information, directing them to a dedicated security address and offering Signal or other encrypted communication channels upon request.

Last week, attackers managed to extract Lightning Network admin macaroon credentials from affected BTCPay Server instances. Lightning macaroons are authorization tokens that grant control over a Lightning node, meaning anyone holding admin-level credentials could move funds routed through that node. The project has published technical details and remediation guidance in a separate security advisory.

"To the users who lost funds: we are sorry," the project said. "We will examine our mistakes, but regret alone will not help affected users or secure the project. There is no time to waste. We have to learn, improve, and act quickly."

The BTCPay Server Foundation announced it would donate 0.21 bitcoins to Sparrow Wallet developer Craig Raw and an additional 0.21 bitcoins to the Bitcoin Red Team fund in recognition of their responsible disclosure of the vulnerability.

Separately, the project stated it has been contacted by security teams at exchanges, blockchain analytics firms, and law enforcement agencies offering assistance in tracking the stolen coins.

Affected users who have not yet come forward are being asked to share on-chain addresses and transaction details, file reports with local authorities, and notify any exchange or service where the funds might surface. Individual reports help preserve records and establish a chain of evidence that improves the likelihood of funds being frozen, the project noted.

The project also warned that improving AI models are making it faster and cheaper for adversaries to comb large codebases for weaknesses, shifting the balance toward attackers. Bitcoin projects are feeling this impact first because they represent unusually valuable targets, according to the statement.