BTCPay Server Supporters Offer 3 BTC Bounty After Critical LND Exploit
A recovery reward of 10% of retrieved assets has been pledged following a vulnerability that granted attackers full control over Lightning Network wallets.
Supporters of the open-source Bitcoin payment processor BTCPay Server have launched a recovery bounty to retrieve funds stolen in a critical security exploit. The initiative offers a reward of 10% of any recovered assets, capped at 3 BTC, as the community attempts to mitigate the impact of the breach.
The vulnerability targeted LND admin macaroon credentials, which serve as the primary authentication keys for Lightning nodes. By stealing these credentials, attackers gained full administrative control over connected Lightning Network wallets. The flaw affected all BTCPay Server releases prior to version 2.4.2. In response, BTCPay released version 2.4.2 to patch the hole and urged all users to upgrade their systems immediately. Affected entities included the publication Citadel21 and the hardware wallet manufacturer Foundation.
The Rise of AI Auditing
This incident arrives amid a broader surge in security threats targeting the Bitcoin ecosystem. It follows a significant firmware flaw in Coldcard hardware wallets that exposed substantial funds, with reports estimating losses between $38 million and $70 million.
There is a growing trend of utilizing AI-assisted code analysis to identify vulnerabilities in open-source repositories. The Bitcoin Red Team recently demonstrated the scale of this shift, using AI models to conduct audits that identified 4,962 issues across 390 Bitcoin projects in approximately 27.5 hours. To acknowledge the role of researchers in securing the network, the BTCPay Server Foundation donated 0.21 BTC each to the Bitcoin Red Team fund and researcher Craig Raw for reporting the flaw.
Industry Implications
This exploit underscores a critical shift in the threat landscape, where AI is significantly reducing the time and cost required for attackers to find complex vulnerabilities in high-value software. The compromise of a widely used tool like BTCPay Server highlights the fragility of decentralized infrastructure when faced with automated discovery tools. For the industry, it signals an urgent need for more rigorous, AI-aware code scanning and the implementation of faster patching cycles to stay ahead of adversarial AI.
Future Outlook
As the community seeks to recover the stolen funds through the 10% bounty, the focus remains on the widespread adoption of version 2.4.2. Security experts will be watching to see if the Bitcoin Red Team's AI-driven approach leads to a wave of further disclosures across other Bitcoin-related projects. While the immediate flaw is patched, the incident serves as a warning that the speed of vulnerability discovery is now accelerating beyond traditional manual audit capabilities.