BTCPay Server is offering a bounty worth up to 3 Bitcoin for information leading to the recovery of funds stolen in a wallet exploit that drained Lightning nodes running its software. The reward is structured as 10% of any recovered funds, capped at 3 BTC, and the open-source payment processor says it will accept tips from anyone with actionable information — including the attacker themselves.
The underlying vulnerability let unauthenticated remote attackers extract Lightning Network admin macaroon credentials — the API keys LND nodes use to authenticate — from affected BTCPay Server instances, giving attackers control over victims' Lightning channels and the ability to move funds out.

A Patch That Doesn't Undo the Damage
BTCPay Server confirmed the flaw was being actively exploited and shipped version 2.4.2 to close it on August 7. But the project's security advisory makes clear that updating alone does not protect operators whose macaroon files were already stolen before the patch: those credentials remain valid until an operator manually revokes and regenerates them and moves funds out of any BTCPay-generated on-chain hot wallet. Foundation, maker of the Passport hardware wallet, and merchant node operator Citadel21 both confirmed their Lightning nodes were swept before BTCPay's public warning went out, illustrating how narrow the window was between disclosure and exploitation.
"Regret Alone Will Not Help"
To the users who lost funds: we are sorry. We will examine our mistakes, but regret alone will not help.
The project said it has engaged security teams at exchanges, blockchain analytics firms, and law enforcement agencies to trace the stolen funds, and is asking affected users to file reports with authorities and share on-chain addresses tied to the theft. Alongside the recovery bounty, BTCPay separately donated 0.21 BTC to Sparrow Wallet developer Craig Raw and another 0.21 BTC to the Bitcoin Red Team fund, both tied to responsible-disclosure work.
Related: Riot Platforms Lands $9.1B Anthropic Data Center Lease
Security Over New Features, Indefinitely
BTCPay says it will prioritize security patches over new feature development for the foreseeable future, and pointed to a broader trend it sees working against defenders: increasingly capable AI models are making it faster and cheaper to discover code vulnerabilities, an advantage the project argues currently favors attackers over small open-source teams. Bitcoin infrastructure projects, given the direct monetary value at stake, are a particularly attractive target for that kind of automated vulnerability hunting.