BTCPay Server supporters offer up to 3 BTC for recovery bounty after critical exploit
·2 min read
Compiled by KHAO Editorial
— aggregated from 4 sources + 4 references discovered via search.
See llms.txt for citation guidance.
✓ KHAO Verified
Supporters of BTCPay Server, the open-source bitcoin payments processor that recently disclosed an exploit, have committed to supporting a recovery bounty of 10% of any funds recovered, capped at 3 BTC for full recovery, according to an announcement on Monday.
Key facts
Chainalysis estimated that $36.7 million was stolen from unverified, closed-source smart contracts in the first six months of 2026 by decompiling their bytecode, which likely required AI
The BTCPay Server Foundation is donating 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for discovering and privately reporting the critical vulnerability to BTCPay
BTCPay Server announced on Friday that a critical vulnerability was being actively exploited and urged users to update their servers to version 2.4.2
Supporters of BTCPay Server, the open-source bitcoin payments processor that recently disclosed an exploit, have committed to supporting a recovery bounty of 10% of any funds recovered, capped at 3
Summary
BTCPay Server announced on Friday that a critical vulnerability was being actively exploited and urged users to update their servers to version 2.4.2. “The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project wrote on X. In other words, a security flaw let attackers steal the master access keys from certain Bitcoin payment servers, giving them full control over any linked Lightning wallets. “Users of other Lightning implementations and users who do not use Lightning do not need to update to address this LND credential risk, but we strongly encourage them to update BTCPay Server,” BTCPay said.