BTCPay Offers $190K Bounty After Lightning Wallet Drain
BTCPay Server announces a $190K bounty after attackers stole LND credentials and drained merchant Lightning wallets last week. The project will pay 10% of recovered funds, up to 3 BTC, as it investigates the security breach and seeks to restore user trust.
Quick Take
BTCPay pledges 10% bounty (up to 3 BTC) for recovering stolen funds.
Hackers compromised LND credentials to drain Lightning wallets.
The breach raises security concerns for Lightning Network payment services.
BTCPay is investigating the breach while calling for better security practices.
Market Impact Analysis
BearishSecurity breach in BTCPay servers may undermine confidence in Lightning Network payment solutions, creating short-term negative sentiment for Bitcoin.
Speculation Analysis
Key Takeaways
- BTCPay Server is offering up to 3 BTC—roughly $190,000—for information leading to the recovery of stolen Lightning funds.
- Attackers compromised LND credentials to drain merchant Lightning wallets from BTCPay servers last week.
- The breach exposes critical security gaps in self-hosted Bitcoin payment infrastructure.
- BTCPay is investigating the incident and calling for enhanced security practices across the Lightning Network.
What Happened
BTCPay Server, the popular open-source Bitcoin payment processor, suffered a security breach last week. Attackers stole LND credentials from merchants’ self-hosted servers and drained their Lightning Network wallets. In response, BTCPay announced a bounty of up to 3 BTC—approximately $190,000—for information leading to the recovery of stolen funds. The project is actively investigating the attack vector and coordinating with affected users. The incident highlights vulnerabilities within self-custodial payment infrastructure, undermining confidence in Lightning Network deployments.
The Numbers
BTCPay is offering 10% of any recovered amount, capped at 3 BTC. With Bitcoin trading near $63,300, the maximum bounty is roughly $190,000. This implies the attackers may have drained up to 30 BTC—equivalent to $1.9 million—if the bounty cap was set against full recovery. The exact amount stolen remains undisclosed. The breach reflects broader Lightning Network risks, where total capacity exceeds 5,000 BTC, but individual node security remains a user responsibility.
Why It Happened
The breach likely resulted from poor security practices on self-hosted BTCPay instances. Many merchants run their own servers, potentially exposing LND credentials through misconfigured APIs or weak authentication. Attackers targeted these weak points to remotely access wallets. The incident underscores the persistent challenge of securing Lightning nodes—a burden that falls entirely on operators. As Bitcoin payment infrastructure attracts more value, such attacks are expected to intensify.
Broader Impact
This breach could slow merchant adoption of Lightning Network payments, especially among those lacking technical expertise. BTCPay’s transparent bounty and investigation may set a precedent for community-driven incident response. However, the incident fuels bearish sentiment around Bitcoin’s layer-2 security, with short-term market reactions reflecting renewed caution.
What to Watch Next
- Whether the bounty yields actionable intelligence and leads to recovery of funds.
- BTCPay’s forthcoming security patches and guidelines to harden self-hosted nodes.
- Impact on BTCPay adoption and overall Lightning Network transaction volumes in the weeks ahead.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.