A vulnerability in versions prior to 2.4.2 exposed LND credentials of connected Lightning nodes; the community responds with a recovery bounty and the BTCPay Server Foundation rewards the researchers who disclosed it.
Supporters of BTCPay Server announced on Monday 11 August 2026 a recovery bounty equal to 10% of returned funds, capped at 3 BTC in the event of full recovery. The mechanism is intended for victims of the exploit disclosed on Friday 8 August.
According to the project’s security advisory, all versions of BTCPay Server prior to 2.4.2, including release candidates of that version, contained a vulnerability that allowed an attacker to obtain LND admin macaroon credentials from affected instances. With those credentials, an attacker gained full access to connected Lightning nodes and their associated wallets. On-chain wallets, including hot wallets, were not compromised. Users running Lightning implementations other than LND, or not using Lightning at all, are not exposed to this specific risk, though the team nonetheless recommended updating.
Among the affected nodes are those of Foundation and Citadel21, whose operators publicly confirmed the draining of funds. BTCPay has not disclosed the total amount stolen or the number of nodes affected.
The BTCPay Server Foundation has allocated 0.21 BTC each to security researcher Craig Raw – developer of Sparrow Wallet and himself among the victims – and to the Bitcoin Red Team, the volunteer researcher group comprising Rob Hamilton, Calle, and Evan Kaloudis, for responsible disclosure of the vulnerability. A detailed postmortem is in preparation, and the team announced the introduction of more robust code-scanning processes with support from external organisations.
BTCPay also indicated that artificial intelligence may have accelerated the discovery of the vulnerability. The same attack vector had emerged in the Coldcard case and, shortly before, with Boltz, which was forced to suspend swaps following AI-assisted attacks. BTCPay Server version 2.4.2 is available and resolves the vulnerability.





