Summary

  • Supporters of BTCPay Server have pledged 10% of any recovered funds, with a maximum of 3 BTC.
  • The breach involved Bitcoin theft using credentials from compromised LND servers.
  • Those using the affected software are urged to upgrade to version 2.4.2 immediately.

Supporters of BTCPay Server have announced a bounty of 10% on any recovered Bitcoin, limited to 3 BTC, equivalent to approximately $190,000, for the return of funds taken during a recent security breach.

In a message posted on X this past Monday, BTCPay stated that the offer is available to anyone who can provide information leading to the recovery of the stolen funds, including the perpetrator.

“We will review our errors, but mere regret will not assist affected users or safeguard the project,” the organization stated. “Time is of the essence. We must learn, enhance, and act swiftly.”

BTCPay initially alerted users about the attacks on Friday, urging them to install an updated version, 2.4.2, or to take their servers offline. At that time, the organization had not confirmed any thefts or detailed the nature of the exploit.

According to BTCPay, the vulnerability enabled attackers to acquire LND admin macaroons—credentials that provide extensive control over a Lightning Network node—and utilize them to access linked wallets. The Lightning Network operates as a layer-2 payment solution on the Bitcoin blockchain, facilitating quicker and more economical transactions by routing payments through channels between users.

BTCPay has not revealed the total amount of Bitcoin stolen, the number of users impacted, or whether any funds have been retrieved.

If multiple tips lead to the recovery of the stolen funds, the bounty will be split among the victims based on their losses, the amount recovered, and the relevance of each tip.

Additionally, the BTCPay Server Foundation will donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for their responsible disclosure of the vulnerability.

“These contributions may be modest, but they represent what we can offer as a free and open-source software project, as well as a way to acknowledge individuals performing essential security work that benefits the entire ecosystem,” BTCPay commented.

The organization is also enhancing its code review processes and prioritizing security updates over new features, as they recognize that AI is making it increasingly easier for attackers to exploit vulnerabilities in Bitcoin software.

“Safeguarding software in this landscape demands improved tools, more comprehensive reviews, quicker security responses, and support for researchers who identify and responsibly report vulnerabilities,” BTCPay concluded.

Daily Debrief Newsletter

Stay updated with the latest news stories, along with original features, podcasts, videos, and more.