Loading prices…
🩸BEARISH

BTCPay Offers $190K Bounty for Lightning Wallet Attack

The $190K cap is the headline, but the real story is LND as a single-vendor credential risk now that attackers have demonstrated a working drain against the dominant Lightning node stack.

BTCPay Offers $190K Bounty for Lightning Wallet Attack
BTCPay Offers $190K Bounty for Lightning Wallet Attack
BTCPay Offers $190K Bounty for Lightning Wallet Attack
BTCPay Offers $190K Bounty for Lightning Wallet Attack

BTCPay Server is offering a bounty equal to 10% of any recovered stolen bitcoin, capped at 3 BTC (worth roughly $190,000 at current prices), to anyone with information that leads to the return of funds drained from merchant Lightning wallets last week. The offer is open to the public, including the attacker. Attackers exploited a vulnerability that let them obtain LND Lightning node credentials and drain connected wallets, hitting hardware-wallet maker Foundation and bitcoin publication Citadel21.

Why it matters

The exploit targeted LND, the dominant software stack for running a Lightning node, which means the threat surface extends well beyond BTCPay's own deployments. Any merchant running LND with weak credential hygiene is exposed to the same class of attack. The vulnerability was identified by the Bitcoin Red Team, a volunteer group that began using AI tools this month to scan bitcoin codebases and has filed thousands of findings across hundreds of projects. The new AI-driven research cadence is compressing the window between discovery and disclosure, but the same tooling is increasingly available to attackers hunting the same bug classes.

Market impact

Foundation and Citadel21 have confirmed losses, but neither BTCPay nor the victims have published a total so far. The project is now coordinating with exchanges, blockchain analytics firms and law enforcement to trace the funds, while urging affected merchants to file police reports and to keep the bulk of holdings in cold storage. BTCPay is also donating 0.21 BTC each to developer Craig Raw and the Bitcoin Red Team fund for the responsible disclosure. The incident is a reminder that Lightning remains operationally fragile for non-custodial merchants: every credential leak is a total-loss event, and the recovery path runs through on-chain analytics, not back through the Lightning channel.

Related tokens
$BTC

Frequently asked questions

  1. What happened to BTCPay merchants?

    Attackers exploited a vulnerability that let them obtain LND Lightning node credentials and drain connected wallets belonging to BTCPay merchants, including hardware-wallet maker Foundation and bitcoin publication Citadel21.

  2. How much bitcoin was stolen?

    BTCPay and the victims have not published a total so far. The project is offering a bounty worth up to 3 BTC (~$190,000) for information leading to recovery.

  3. What is the Bitcoin Red Team?

    A volunteer effort that began using AI tools this month to scan bitcoin codebases, filing thousands of findings across hundreds of projects. The team disclosed the LND credential vulnerability BTCPay patched.

  4. Who is the bounty open to?

    Anyone with useful information, including the attacker. If multiple reports lead to a recovery, the bounty is split among victims based on losses and how useful each tip proved.

  5. What should Lightning merchants do now?

    BTCPay is urging affected merchants to file police reports, coordinate with any service the funds touch, and keep the bulk of holdings in cold storage rather than hot Lightning wallets.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →