BTCPay Offers Recovery Bounty After Critical Wallet-Credential Exploit

Supporters will pay 10% of recovered funds, capped at three bitcoin, as the open-source processor shifts resources from features to security.

By Ingrid Solberg • • Blockchain

A fractured dark payment conduit being repaired beside a protected illuminated vault

BTCPay Server and its supporters have offered a recovery bounty after attackers exploited a critical vulnerability that exposed administrative credentials for connected Lightning wallets. The reward is set at 10% of funds returned, capped at three bitcoin, and forms part of a wider response that includes researcher payments and a security-first development plan.

The project said supporters would fund the recovery incentive while exchanges, blockchain-analysis companies and law-enforcement agencies assist in tracing stolen assets. BTCPay also announced donations of 0.21 bitcoin each to security researcher Craig Raw and the Bitcoin Red Team for responsible disclosure work related to the vulnerability.

The underlying security warning was issued on August 7, before this edition's 24-hour window. BTCPay told operators to upgrade immediately to version 2.4.2 or shut down their servers. The new development inside the window is the project's recovery and compensation response, including the bounty and its commitment to prioritise security patches over new features.

Reports describe the flaw as exposing LND admin macaroon credentials. In the Lightning Network, a macaroon functions as an authorisation credential with defined permissions. An administrative credential can give broad control over a node and connected wallet operations. If an attacker extracts it from a vulnerable server, self-custody at the application level no longer protects the funds controlled by that credential.

BTCPay is widely used because it allows merchants to accept bitcoin and Lightning payments without handing custody to a conventional payment processor. That architecture removes an intermediary, but it moves more operational responsibility to the server operator. Patching, credential isolation, wallet configuration and the separation of hot and cold funds become direct financial controls rather than back-office technical tasks.

The incident exposes a difficult trade-off in open-source payments. Public code allows researchers to inspect systems and submit fixes, while decentralised deployment reduces dependence on one hosted provider. At the same time, thousands of independently managed installations can remain on old versions, and the project cannot force an emergency update. An exploit can therefore continue to find vulnerable servers after a patch exists.

The bounty is designed to recover assets, not identify the full loss. Neither BTCPay nor the affected users had disclosed a complete aggregate figure at the cutoff. A reward capped at three bitcoin does not establish how much was stolen. The return rate, attacker response and ability of tracing firms to connect addresses to regulated services will determine whether the incentive has practical effect.

The donations to researchers also matter. This publication previously covered the Bitcoin Red Team's AI-assisted audit and warned that maintainers faced a triage bottleneck. The BTCPay exploit is a material follow-up: one of those research efforts is now connected to a patched critical flaw, real losses and a recovery process. Paying for responsible disclosure helps align incentives toward reporting vulnerabilities before publishing details that could endanger unpatched users. BTCPay's promise to place security ahead of feature development acknowledges that a payment system's value depends first on protecting funds.

Merchants need to treat the patch as only the first step. Operators should verify that every instance is running version 2.4.2 or later, rotate potentially exposed credentials, review logs and wallet movements, report losses to relevant authorities, and move excess balances out of internet-connected wallets. A patched application cannot reverse transactions already authorised with stolen credentials.

The incident may also influence how businesses deploy self-hosted payment infrastructure. Some will continue to value control and censorship resistance but add managed security, monitoring and cold-storage policies. Others may decide that operational risk outweighs the benefit of avoiding a hosted provider. The likely result is not the end of self-custody, but a clearer distinction between possessing keys and maintaining secure systems around them.

Why it matters

BTCPay sits at the practical edge of bitcoin commerce, where software vulnerabilities can become direct and irreversible financial losses. The recovery response shows the strengths of an open-source community, including rapid disclosure, researcher funding and collective tracing. It also shows the limits: projects cannot patch independent servers automatically or restore funds after credentials are compromised. Security operations are part of custody, even when no central custodian exists.

Sources