The security breach originated from a flaw that exposed LND admin macaroon credentials, granting attackers unauthorized control over associated Lightning wallets. BTCPay Server patched the vulnerability in version 2.4.2 and urged all operators to update immediately. While the project has not disclosed the total volume of stolen funds, users including Foundation and Citadel21 confirmed their nodes were swept by attackers targeting the exposed credentials.
In section Cryptocurrency
BTCPay Server Offers 10% Bounty for Recovery of Stolen Bitcoin
Supporters of the open-source payment processor BTCPay Server have authorized a bounty equal to 10% of any funds retrieved following a recent exploit that drained connected Lightning nodes. The reward is capped at 3 BTC, providing a financial incentive for the return of assets lost in a critical credential theft.
Onchain wallets remained secure throughout the incident, as the exploit was isolated to the Lightning Network implementation. To bolster future security, the BTCPay Server Foundation is implementing rigorous code-scanning procedures. The project also rewarded researchers who identified the flaw before public disclosure, donating 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team. BTCPay officials noted that the sophistication of the attack suggests the potential use of AI-assisted code analysis, a growing threat vector that recently surfaced in similar exploits involving Coldcard hardware wallets.
Comments (0)
No comments yet. Be the first!