
BTCPay Offers $190,000 Bounty After Lightning Wallet Exploit
BTCPay announced a bounty of up to 3 BTC (approximately $190,000) for recovery of funds stolen in a recent exploit targeting its payment servers. Attackers obtained Lightning Network daemon credentials and drained merchant wallets hosted on the platform.
Written by CoinArticle’s AI Newsroom · from 1 cited source. How we work
The Exploit and Bounty Terms
BTCPay announced Monday it will pay 10% of any recovered funds, capped at 3 BTC, following a breach that exposed LND (Lightning Network daemon) credentials on its servers. The stolen credentials gave attackers access to merchant Lightning wallets, resulting in unauthorized withdrawals. The bounty structure incentivizes third parties—security researchers, law enforcement, or recovery specialists—to help trace and retrieve the drained funds.
Scope of the Incident
The attack specifically targeted BTCPay's hosted payment server infrastructure, compromising Lightning wallets that merchants used for accepting bitcoin payments. While the exact number of affected merchants and total amount stolen has not been disclosed, the size of the bounty suggests losses in the range of $1.9 million or more. BTCPay is a self-hosted payment processor known for giving merchants control over their own private keys, but the company also offers a hosted option where users delegate key management to the platform.
Why It Matters
For Traders
Merchants using BTCPay's hosted service should audit their Lightning balances immediately; credential compromise may have exposed wallets beyond those already drained.
For Investors
The incident highlights custody risk in payment processors and may accelerate demand for non-custodial payment rails, pressuring platforms that hold keys.
For Builders
Payment infrastructure teams should review credential rotation policies and consider hardware security modules or threshold custody to reduce single-point-of-failure exposure.
This article is for information only and is not financial advice. Read the full disclaimer.






