BTCPay Server Offers $190K Bounty After Lightning Wallet Exploit Drains Merchant Funds

BTCPay Server has posted a recovery bounty of up to 3 bitcoin (BTC), roughly $190,000, after attackers pulled Lightning Network credentials from self-hosted merchant payment nodes last week and emptied their on-chain and channel balances.

The bounty pays 10% of any recovered funds, capped at 3 BTC, according to a project security advisory. No total for the stolen amount has been disclosed. BTCPay has not said how many merchants were affected. Anyone with information, including the attacker, can reach the project through a dedicated Bitcoin address, with encrypted-channel contact available on request, Bitcoin Magazine reported.

The attack hit BTCPay Server, an open-source, self-hosted bitcoin payment processor that lets merchants accept BTC without a third-party intermediary. Attackers extracted admin macaroon credentials from affected instances, per the project’s post-mortem. Those tokens authenticate Lightning Network Daemon (LND) operations. They were used to drain merchant Lightning wallets. How the credentials were extracted has not been stated.

Craig Raw, developer of Sparrow Wallet, and the Bitcoin Red Team fund reported the vulnerability. Each received 0.21 BTC, roughly $13,000 at recent prices, as an intermediary reward, BTCPay said.

The Block reported the attack may have involved AI-assisted exploitation. BTCPay did not rule it out. The project wrote that improving AI models make it faster and cheaper to comb large codebases for weaknesses, “shifting the balance toward attackers,” and that Bitcoin projects are feeling it first because they are “unusually valuable targets.”

That claim has not been tied to a specific tool or model. BTCPay has not said what evidence, if any, supports the AI-assisted angle. It is the second time in as many weeks that self-custody infrastructure has drawn scrutiny. The earlier Coldcard hardware-wallet incident, which prompted the formation of the Bitcoin Red Team after it surfaced 85 critical flaws across 390 open-source repositories, is a separate event.

Exchanges, blockchain analytics firms, and law-enforcement agencies have contacted the project to help track the stolen coins, according to Bitcoin Magazine. Affected users have been asked to share on-chain addresses and transaction details, file reports with local authorities, and flag any exchange where funds surface. “Individual reports… help preserve records and establish a chain of evidence that improves the odds of funds being frozen,” BTCPay said.

The project is pivoting to security-first development. BTCPay said it will not ship new features until the vulnerability and related issues are patched, and will make security patches its priority going forward.

“To the users who lost funds: we are sorry,” the project said in a statement. “We will examine our mistakes, but regret alone will not help affected users or secure the project. There is no time to waste. We have to learn, improve, and act quickly.”

What is not known: the total value stolen, the number of affected merchants, the specific version or versions of BTCPay Server that were vulnerable, and the mechanism by which credentials were extracted. The AI-assisted-exploitation claim remains unconfirmed by the project beyond its general statement on model capability.

> ABOUT_THE_AUTHOR _

James Chatfield

// Senior News Editor

I lead the editorial team covering digital assets and blockchain regulation at CryptoWatchDaily. After earning a Journalism degree from The University of Sheffield, I spent a decade reporting on traditional finance before shifting focus to crypto. I value accuracy and clarity over hype. When I’m not tracking market movements, I enjoy distance running and collecting vintage sci-fi novels.

VIEW_PROFILE >>