BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

$190,000 Bitcoin bounty up for grabs and the thief is invited to collect

BTCPay Server, the free, self-hosted software many merchants use to accept Bitcoin, disclosed on Aug. 7 that a critical vulnerability was being actively exploited against live servers — and t

AnonymousCryptoCompass newsroom
August 11, 2026
4 min read
NEWS
$190,000 Bitcoin bounty up for grabs and the thief is invited to collect
CryptoCompass editorial visual for bitcoin coverage.

BTCPay Server, the free, self-hosted software many merchants use to accept Bitcoin, disclosed on Aug. 7 that a critical vulnerability was being actively exploited against live servers — and that some users had already lost funds.

The project said the vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and gain access to connected Lightning Network wallets. 

In simple terms, the flaw handed attackers the keys to the Lightning node behind a merchant's payment server, letting them move the money out. The bug affects every version before 2.4.2, and confirmed victims include the maker of the Passport hardware wallet, Foundation, and the publication Citadel21, whose nodes were swept before the public warning went live. BTCPay has not said how much was stolen or how many servers were hit.

Related: U.S. Treasury to share cyber alerts with eligible exchanges

Technical details and remediation steps have been published in a security advisory on X.

Users who have not updated are urged to move immediately to version 2.4.2, which also refreshes LND and regenerates the admin macaroon. Crucially, the project warns that updating alone is not enough: the patch stops new access but does not invalidate credentials already stolen, so operators must also revoke their LND macaroons and move funds out of any BTCPay-generated hot wallet.

"To the users who lost funds: we are sorry. We will examine our mistakes, but regret alone will not help affected users or secure the project. There is no time to waste. We have to learn, improve, and act quickly."

Recovery bounty details

Friends and supporters of the project have committed funds for a bounty equal to 10% of any amount recovered, capped at a maximum of 3 BTC — roughly $190,000 at recent prices — if the full sum is returned.

The offer is open to anyone with actionable information that could lead to recovery, including the attacker. Secure channels such as Signal can be arranged on request. If multiple tips contribute, the bounty will be split based on usefulness of the information, amounts lost and recovered, and other factors, in coordination with the victims.

Separately, the BTCPay Server Foundation is donating 0.21 BTC to Sparrow Wallet developer Craig Raw and another 0.21 BTC to the Bitcoin Red Team for their responsible disclosure of the flaw. Raw discovered the issue and reported it privately, giving developers time to prepare a fix before details became public.

"The BTCPay Server Foundation will donate 0.21 BTC to Craig Raw and 0.21 BTC to the Bitcoin Red Team fund for their responsible security disclosure of the vulnerability. These are modest contributions."

Related: What happens to your money if dollar collapses? Michael Saylor has an answer

Next steps for affected users

Impacted users who have not yet reported are asked to email the project's security address with on-chain addresses and transaction details. The project also advises filing reports with local authorities and contacting any exchanges or services where the stolen funds may appear; individual reports help build a clearer evidence trail and raise the chance of freezes.

BTCPay Server said it is working with exchange security teams, blockchain analytics firms and law enforcement. Going forward, the project will prioritize security patches and hardening over new features, and it recommended keeping excess funds in cold storage rather than in hot wallets connected to a payment server.

The team said the incident underscores the growing challenge of defending open-source Bitcoin software as AI tools make vulnerability hunting faster and cheaper. It also lands during a rough stretch for Bitcoin infrastructure, coming just days after a separate exploit tied to a firmware flaw drained tens of millions of dollars from Coldcard hardware-wallet users.

Related: If you invested $1,000 in gold, Bitcoin and $TRUMP on Inauguration Day, here is what each is worth today