← Back

security

BTCPay Offers $190,000 Bounty Following Bitcoin Payment Server Exploit

BTCPay has announced a $190,000 bounty after attackers drained merchant Lightning wallets by stealing LND credentials. The project commits to paying 10% of recovered funds, up to 3 BTC.

AS1 NewsSource: coindesk.com

securitylightning-networkbitcoinpayment-processingcyberattackvulnerability
BTC$77,771.00+1.44%

BTCPay, a popular open-source payment processor for Bitcoin, has disclosed a security incident where malicious actors compromised its bitcoin payment servers. The attackers managed to steal Lightning Network Daemon (LND) credentials, leading to the draining of merchant Lightning wallets. The breach occurred last week, prompting BTCPay to respond swiftly.

In an effort to recover the stolen funds and enhance security, BTCPay has announced a bounty of $190,000. The project states it will pay 10% of any recovered funds, with a maximum of 3 BTC, to those who assist in the recovery process. This initiative aims to incentivize security researchers and the community to help identify the breach's source and prevent future incidents.

The incident highlights ongoing security challenges within the Lightning Network ecosystem, especially for open-source projects that facilitate Bitcoin transactions. While the specifics of the breach are still under investigation, the event underscores the importance of robust security measures for Lightning node operators and payment processors.

BTCPay has emphasized its commitment to transparency and security, working closely with security experts to address the vulnerabilities exploited in this attack. The community is advised to remain vigilant and ensure their Lightning wallets and credentials are securely managed.

negative

The breach resulted in the draining of Lightning wallets associated with BTCPay's payment servers, highlighting security vulnerabilities in Lightning Network implementations.