📈 Get daily crypto insights that make you smarter about your money

BTCPay Server Offers 190K Bounty After Lightning Exploit Drains Merchant Wallets

A popular Bitcoin payment processor just offered a 190,000 US dollar bounty to whoever can help recover stolen funds — and the offer is open even to the attacker. The BTCPay Server exploit that drained merchant Lightning wallets last week has exposed how even open-source infrastructure trusted by thousands of merchants can become a single point of failure.

By Marcus Johnson | August 11, 2026

The Hook: When Your Payment Processor Becomes the Vulnerability

BTCPay Server, the volunteer-maintained Bitcoin payment processor used by merchants worldwide, announced Tuesday it is funding a bounty worth up to 3 BTC — roughly 190,000 US dollars at current prices — for information leading to the recovery of bitcoin stolen from merchants last week. The offer is open to anyone with useful information, including the attacker responsible for the theft.

The bounty terms are straightforward: the reward equals 10 percent of whatever stolen funds are recovered, capped at 3 BTC. If multiple tips contribute to a recovery, the bounty will be split between the tipsters and the victims based on how much each lost and how useful each piece of information proves to be. The project asked anyone with relevant information to contact its security address, with secure communication channels available on request.

On-Chain Evidence: How the Attack Unfolded

The attack exploited a vulnerability in BTCPay Server that allowed attackers to obtain credentials for LND — short for Lightning Network Daemon, the most widely used software for running Lightning Network nodes. Lightning is Bitcoin’s layer-2 scaling solution, designed to enable fast and cheap payments by routing transactions through a network of payment channels rather than settling every transaction on the blockchain.

Once the attackers had the LND credentials, they could drain the Lightning wallets connected to the compromised BTCPay instances. At least two merchants have publicly disclosed losses: Foundation, a hardware wallet manufacturer, and Citadel21, a Bitcoin-focused publication. Neither BTCPay nor the victims have published the total amount stolen.

Key details about the response:

  • Bounty capped at 3 BTC — Worth approximately 190,000 US dollars at current bitcoin prices around 63,500 US dollars.
  • Researchers compensated — BTCPay donated 0.21 BTC each to developer Craig Raw and the Bitcoin Red Team for their responsible disclosure of the vulnerability.
  • Law enforcement involved — Exchanges, blockchain analytics firms, and law enforcement agencies have all offered assistance in tracing the stolen funds.
  • Merchants urged to act — BTCPay advised affected merchants to report the theft to local police and to any exchange or service the funds might be traced to.

The Core Conflict: Open Source Means Shared Risk

The BTCPay exploit highlights a tension at the heart of Bitcoin’s merchant ecosystem. BTCPay Server is free, open-source software maintained by volunteers. It is widely trusted precisely because its code is public and anyone can inspect it. But open-source infrastructure still requires active maintenance, prompt patching, and — as this incident shows — robust security practices from every merchant running the software.

The vulnerability that enabled this attack was identified by researchers tied to the Bitcoin Red Team, a volunteer effort that began using AI models to scan Bitcoin codebases for bugs earlier this month. The team has filed thousands of findings across hundreds of projects, including the report that led to the BTCPay patch. The fact that AI-accelerated code review discovered the flaw is both reassuring and concerning: reassuring because it means more vulnerabilities are being caught, but concerning because it suggests the attack surface is larger than previously understood.

BTCPay itself acknowledged the shifting landscape, advising merchants to keep the majority of their funds in cold storage — wallets that are completely offline — and to regularly move excess balances out of hot wallets. The project specifically noted that this practice is essential “especially during this period of rapid, AI-driven change,” a reference to the growing use of AI tools by both security researchers and attackers.

Market Implications: What This Means for Bitcoin Merchants

For the thousands of merchants who accept Bitcoin through BTCPay Server or similar platforms, this incident is a wake-up call. The Lightning Network promises near-instant, low-cost Bitcoin payments, but it requires merchants to keep funds in hot wallets — wallets connected to the internet — to maintain payment channels. That creates an inherent tension between convenience and security.

The good news is that the attack targeted a specific vulnerability in BTCPay’s implementation, not in the Lightning Network protocol itself or in Bitcoin’s base layer. Merchants using other Lightning implementations or different payment processors were not directly affected. The bad news is that BTCPay is one of the most popular self-hosted Bitcoin payment solutions, meaning the blast radius could be significant.

For Bitcoin investors, the incident is a reminder that infrastructure risk remains one of the most underappreciated threats in the crypto ecosystem. While most market attention focuses on price volatility and regulatory developments, the plumbing that makes Bitcoin usable as a currency — payment processors, Lightning node software, wallet applications — is still maturing, and vulnerabilities in that plumbing can erode merchant confidence and slow adoption.

The Verdict: Security Is Everyone’s Job

The BTCPay bounty is an unusual but pragmatic response to a difficult situation. By offering the attacker a way to return funds for a percentage cut, BTCPay is acknowledging a reality of the crypto world: once bitcoin moves, recovering it through conventional law enforcement channels is difficult and slow. The bounty mechanism creates an economic incentive for cooperation that does not depend on the legal system.

For merchants, the lesson is clear. Self-custody is powerful, but it comes with responsibility. Hot wallets should hold only what you need for day-to-day operations. The rest belongs in cold storage. Regular security audits — even informal ones — can catch vulnerabilities before attackers do. And when you are running open-source software, staying up to date with patches is not optional; it is the cost of doing business.

The Bitcoin Red Team’s AI-driven approach to code auditing could become a standard practice across the industry. If thousands of vulnerabilities are being found by pointing AI models at existing codebases, the entire ecosystem will need to adapt — both by fixing bugs faster and by rethinking how critical infrastructure is built and maintained.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

14 thoughts on “BTCPay Server Offers 190K Bounty After Lightning Exploit Drains Merchant Wallets”

  1. offering the attacker 10% of recovered funds is smart. nobody else is gonna find lightning exploit fingerprints

  2. 10% bounty to the attacker for returning what they stole is wild. basically negotiating with the people who drained your wallets lol

    1. negotiating is better than nothing when law enforcement cant help. once btc moves through a few mixers its gone. 10% is cheap compared to taking a total loss

    2. 10% bounty is not negotiating with thieves, its a recovery strategy. ransomware victims do the same thing. morality aside, it works better than waiting for the FBI

  3. volunteer-maintained payment infrastructure handling real merchant money was always gonna end badly. love the ethos but you need paid security audits when peoples funds are on the line

  4. LND credentials getting compromised because of a BTCPay implementation bug is exactly why I keep telling people to segment their node access. Citadel21 and Foundation losing funds to this hurts the whole space

    1. citadel21 had like 40% of their treasury on a single LND node. segmentation is table stakes not some advanced opsec

      1. null_pointer_88

        40% on one node is insane. any decent devops person wouldve split that across at least 3 LND instances. citadel21 basically ran their treasury like a crypto beginner

      2. @node_op_solo 40% on one LND node is wild. any sysadmin wouldve split that across 3 instances minimum. Citadel21 ran their treasury like a hobby project

    2. klaus is right about segmentation but the real issue is LND credential handling in btcpay. you can segment all you want but if the root access path is the same its one exploit away from total loss

    3. Klaus is right about segmentation but honestly the real failure was LND itself. BTCPay just exposed the surface, the credential handling flaw was upstream

  5. volunteer maintained payment processor handling real merchant funds was always a ticking bomb. love the ethos but this was inevitable

  6. 3 BTC bounty for recovering lightning channel funds is honestly cheap. whoever pulled this off is long gone mixing coins

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,614.00-0.5%ETH$1,880.54+0.3%SOL$76.34+0.3%BNB$614.01+2.5%XRP$1.02+1.0%ADA$0.1866-2.8%DOGE$0.0723+3.6%DOT$0.7879-2.2%AVAX$6.32-1.6%LINK$8.77+5.7%UNI$3.76-4.7%ATOM$1.44+3.0%LTC$45.44+0.7%ARB$0.0793-0.5%NEAR$1.60+0.4%FIL$0.7115+1.3%SUI$0.6918+1.1%BTC$63,614.00-0.5%ETH$1,880.54+0.3%SOL$76.34+0.3%BNB$614.01+2.5%XRP$1.02+1.0%ADA$0.1866-2.8%DOGE$0.0723+3.6%DOT$0.7879-2.2%AVAX$6.32-1.6%LINK$8.77+5.7%UNI$3.76-4.7%ATOM$1.44+3.0%LTC$45.44+0.7%ARB$0.0793-0.5%NEAR$1.60+0.4%FIL$0.7115+1.3%SUI$0.6918+1.1%
Scroll to Top