Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Bitcoin

BTCPay Offers $190,000 Bounty After Bitcoin Wallet Exploit

1 reports · First detected 2026-08-11 · Last active 2026-08-11

BTCPay Server is an open-source, self-hosted payment processor that lets merchants accept bitcoin without relying on a conventional intermediary. Some deployments connect to LND nodes to handle Lightning Network payments, which requires keeping signing credentials on an internet-connected system. The breach exposed those credentials and allowed attackers to drain wallets belonging to several merchants, underscoring the security trade-offs associated with hot wallets and self-managed payment infrastructure.

Volunteer group Bitcoin Red Team identified the flaw using AI-assisted scanning, prompting BTCPay Server to issue a warning on Aug. 7, 2026. On Aug. 10, the project offered a bounty equal to 10% of recovered funds, capped at 3 BTC, or about $190,000. BTCPay said it was working with cryptocurrency exchanges and law-enforcement agencies to trace the stolen bitcoin, while advising merchants to keep most holdings in cold storage.

All Coverage

1 original reports

The Backstory

The history behind this event
BTCPay Server Urges Immediate Update After Critical Exploit2026-08-11 · 8 reports · similarity 0.88

BTCPay Server is a free, open-source, self-hosted Bitcoin payment processor that lets merchants accept on-chain and Lightning Network payments without an intermediary. The incident matters because deployments using LND store .macaroon credentials that can authorize control of a Lightning node. If stolen, those files can let an unauthenticated remote attacker take over the node and transfer funds, exposing the operational risks that accompany self-managed payment infrastructure.

BTCPay Server released version 2.4.2 on Aug. 7, 2026, saying every earlier version, including release candidates, contained the flaw and confirming that attackers had stolen funds from users. LND operators were told to upgrade immediately, verify LND 0.21.1, review balances and unauthorized activity, or take affected servers offline. The project temporarily disabled public LND API access on Docker deployments, while supporters offered a recovery bounty of as much as 3 BTC on Aug. 11. Total losses and the number of victims remain undisclosed.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)