Particle.news
Download on the App Store

BTCPay Server Offers 10% Recovery Bounty Up to 3 BTC After Lightning Macaroon Exploit

The open-source payments project patched the vulnerability, paid the researchers who reported it, sought outside tracing help, offered a capped recovery bounty, and advised operators to rotate credentials and move funds to cold storage.

Overview

  • Attackers exploited a critical flaw that let them extract LND administrator macaroons, the long‑lived credentials used to control Lightning wallets, and used those credentials to drain connected merchant Lightning balances.
  • BTCPay released an emergency fix in version 2.4.2 and published remediation guidance that tells operators to update, rotate macaroons, and move excess hot funds into cold storage.
  • Supporters pledged a recovery bounty equal to 10% of any recovered coins capped at 3 BTC (about $190,000) and the BTCPay Server Foundation donated 0.21 BTC each to Craig Raw and the Bitcoin Red Team for responsible disclosure.
  • Exchanges, blockchain analytics firms and law enforcement have offered assistance tracing the stolen coins while BTCPay collects victim reports and prepares a full post‑mortem, but a total loss figure has not been confirmed.
  • Researchers tied to the volunteer Bitcoin Red Team used AI-assisted code scanning to find the flaw, a development that security teams say is speeding discovery of bugs and raising pressure on self‑hosted merchants to improve wallet hygiene and incident reporting.