Overview
- Attackers exploited a critical flaw that let them extract LND administrator macaroons, the long‑lived credentials used to control Lightning wallets, and used those credentials to drain connected merchant Lightning balances.
- BTCPay released an emergency fix in version 2.4.2 and published remediation guidance that tells operators to update, rotate macaroons, and move excess hot funds into cold storage.
- Supporters pledged a recovery bounty equal to 10% of any recovered coins capped at 3 BTC (about $190,000) and the BTCPay Server Foundation donated 0.21 BTC each to Craig Raw and the Bitcoin Red Team for responsible disclosure.
- Exchanges, blockchain analytics firms and law enforcement have offered assistance tracing the stolen coins while BTCPay collects victim reports and prepares a full post‑mortem, but a total loss figure has not been confirmed.
- Researchers tied to the volunteer Bitcoin Red Team used AI-assisted code scanning to find the flaw, a development that security teams say is speeding discovery of bugs and raising pressure on self‑hosted merchants to improve wallet hygiene and incident reporting.