Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

BTCPay Server Offers Bitcoin Bounty After Lightning Node Hack

BTCPay Server Offers Bitcoin Bounty After Lightning Node Hack. Source: Image by kevin tatchinda fogue from Pixabay

BTCPay Server has announced a bitcoin recovery bounty following last week’s security breach that allowed attackers to drain funds from merchants running Lightning nodes.

The open-source Bitcoin payment infrastructure provider said Tuesday that supporters of the project have committed funds for anyone who can provide information leading to the recovery of the stolen bitcoin. The reward will equal 10% of the amount successfully recovered, capped at 3 BTC, currently worth about $190,000.

The bounty is open to anyone with credible information, including the attacker. BTCPay Server asked potential informants to contact its security team and said secure communication channels can be arranged when necessary.

If information from multiple sources contributes to recovering the stolen bitcoin, the bounty will be distributed based on the victims’ respective losses and the value of each source’s information.

BTCPay Server is also rewarding the security researchers involved in discovering the critical vulnerability. The project said it is donating 0.21 BTC each to Bitcoin developer Craig Raw and the Bitcoin Red Team in recognition of their responsible security disclosure.

Attackers exploited the vulnerability to obtain credentials for LND, widely used software for operating Bitcoin Lightning Network nodes. Those credentials enabled them to access and drain wallets connected to affected systems.

Bitcoin hardware wallet company Foundation and Bitcoin publication Citadel21 have publicly confirmed losing funds in the attack. However, BTCPay Server and affected merchants have not disclosed the total amount of bitcoin stolen.

BTCPay said cryptocurrency exchanges, blockchain analytics companies and law enforcement agencies have offered assistance in tracking the stolen funds. Affected merchants have been encouraged to report the theft to local authorities and notify services that receive funds linked to the attack.

The Bitcoin Red Team, a volunteer security initiative using AI models to examine Bitcoin codebases, identified the issue that resulted in the vulnerability being patched. The group has reported thousands of potential security issues across hundreds of Bitcoin projects.

Following the exploit, BTCPay Server urged merchants to strengthen Bitcoin security practices by keeping most funds in cold storage and regularly transferring excess bitcoin out of hot wallets, particularly as AI-assisted vulnerability research accelerates.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1