started · updated
BTCPay Server offers Bitcoin bounty following wallet exploit
BTCPay Server supporters have announced a recovery bounty of 10% of any retrieved funds, capped at 3 BTC, following a critical security exploit. The vulnerability allowed attackers to obtain LND administrator macaroon credentials, granting them access to connected Lightning Network wallets.
The open-source Bitcoin payment processor has urged all users to immediately upgrade to version 2.4.2 or take their servers offline to prevent further theft. While the project has not disclosed the total amount of cryptocurrency stolen or the number of compromised servers, several users have reported that funds in their Lightning nodes were drained.
In response to the disclosure, the BTCPay Server Foundation is donating 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund for their roles in reporting the flaw. The project is currently preparing a detailed postmortem and noted that artificial intelligence may have played a role in uncovering the vulnerability.
Entities
BTCPay Server · BTCPay Server Foundation · Bitcoin Red Team · Craig Raw · Lightning Network