BTCPay Server announced Tuesday it is funding a recovery bounty of up to 3 BTC — roughly $190,000 at current prices — for information leading to the return of bitcoin stolen from merchants last week through a critical Lightning Network vulnerability.
The bounty, set at 10% of recovered funds, is open to anyone with useful information, including the attacker. The project asked informants to contact its security address, with secure communication channels available on request.
The Exploit
The vulnerability allowed unauthenticated remote attackers to access LND credential files known as ".macaroon" files on BTCPay Server deployments running LND, the most widely used Lightning node software. With those credentials, attackers could seize control of Lightning nodes, close channels, and sweep associated wallets.
Hardware-wallet manufacturer Foundation and Bitcoin publication Citadel21 were among the first to report losses. Neither BTCPay nor the victims have disclosed the total value of stolen funds.
The flaw has been patched in BTCPay Server version 2.4.2. Standard on-chain wallets generated inside BTCPay are not affected — the exposure is limited to LND-connected Lightning wallets.
AI Red Team Credit
The vulnerability was responsibly disclosed by members of the Bitcoin Red Team, a volunteer security initiative that has spent the past week directing AI models at Bitcoin codebases to identify bugs. The group has filed thousands of findings across hundreds of projects.
BTCPay confirmed it is donating 0.21 BTC each to developer Craig Raw and the Bitcoin Red Team fund in recognition of their disclosure.
The initiative has reshaped how the Bitcoin ecosystem thinks about vulnerability discovery. BTCPay advised merchants to keep funds in cold storage and move excess out of hot wallets regularly, "especially during this period of rapid, AI-driven change."
Industry Response
Exchanges, blockchain analytics firms, and law enforcement have offered assistance in tracing the stolen funds. BTCPay urged all affected merchants to report thefts to local police and to any service the funds can be traced to.
The incident follows a string of security issues across Bitcoin infrastructure, including the Coldcard hardware wallet exploit that drained approximately $120 million and the Boltz Bridge shutdown after AI-discovered vulnerabilities. Collectively, these events have raised questions about whether AI-assisted vulnerability discovery is outpacing the ecosystem's ability to patch.