BTCPay Server has launched a bounty of up to roughly $190,000 in hopes of clawing back bitcoin stolen from merchant payment servers, after attackers made off with node credentials and emptied Lightning wallets in a coordinated exploit last week.
What Happened
The open-source payment processor said malicious actors obtained LND (Lightning Network Daemon) credentials belonging to merchants running self-hosted BTCPay instances. Armed with that access, the attackers drained funds held in Lightning wallets connected to those servers.
BTCPay Server is widely used by businesses and individuals who want to accept bitcoin payments without relying on a third-party custodian. Because operators run the software themselves, the theft of node credentials handed attackers direct control over affected wallets.
The project is dangling a reward worth as much as $190,000 in a bid to recover the stolen bitcoin.
The Bounty Offer
In response, the project said it would pay 10% of any recovered funds to those who help return the missing bitcoin, with the reward capped at 3 BTC. At recent prices, that ceiling works out to roughly $190,000.
The structure is designed to incentivize the return of assets, whether through cooperation from the attackers themselves or assistance from security researchers and other parties who can help trace and recover the coins.
- Attackers stole LND credentials from affected servers
- Merchant Lightning wallets were subsequently drained
- BTCPay is offering 10% of recovered funds, up to 3 BTC
Why It Matters
The incident underscores a persistent tension in self-custody: users who avoid custodial platforms take on full responsibility for securing their own infrastructure. When credentials are compromised, there is often no intermediary to reverse or freeze fraudulent transfers.
The episode is likely to renew scrutiny of Lightning Network security practices and credential management for merchants operating their own nodes, as the ecosystem continues to weigh the trade-offs between sovereignty and operational risk.
