Particle.news
Download on the App Store

BTCPay Server Patches Macaroon Leak and Offers 10% Bounty to Recover Stolen Lightning Funds

The project has paid researchers, enlisted exchanges and law enforcement, urged operators to update, rotate credentials, move hot funds to cold storage.

Overview

  • A critical bug in BTCPay Server exposed LND admin macaroon files, which are long‑lived authentication keys that let an attacker control a Lightning node and move funds.
  • Attackers used the weakness to obtain admin macaroons and drain connected Lightning wallets before the project released a fix in version 2.4.2.
  • BTCPay has donated 0.42 BTC to the researchers who privately reported the flaw and launched a recovery incentive that pays 10% of recovered funds up to a 3 BTC cap.
  • The project is coordinating with exchanges, blockchain analytics firms and law enforcement to trace stolen coins and is asking affected operators to report losses and share transaction details.
  • BTCPay is preparing a full postmortem and stronger code‑scanning and review processes after noting that faster AI‑based code analysis can speed both vulnerability discovery and exploitation, and it is urging operators to rotate macaroons and move hot balances into cold storage.