BTCPay Server Hit by Critical Security Flaw Exposing LND Credentials
BTCPay Server users have been hit by a critical security flaw that exposed LND administrator credentials on vulnerable installations. The vulnerability allowed attackers to access connected Lightning wallets, resulting in stolen funds from several affected users.
The BTCPay Server project has since released version 2.4.2 with a fix for the issue and urged operators running older versions to update their servers. However, some users have reported that their Lightning nodes were drained of funds, including Foundation and Citadel21.
As part of its response, the BTCPay Server project is offering a recovery bounty equal to 10% of funds retrieved from the exploit, capped at 3 BTC if all stolen assets are recovered. The project is also donating 0.21 BTC each to researchers Craig Raw and the Bitcoin Red Team fund for discovering and reporting the flaw.
The incident has raised concerns about AI-assisted attacks in the crypto sector, with BTCPay suggesting that improving AI models have reduced the time and cost required to inspect large software repositories for weaknesses.