Summary
- BTCPay Server is offering a bounty of 10% of any recovered stolen bitcoin, up to 3 BTC, to anyone with information leading to the funds’ return, including the attacker.
- The theft stemmed from a vulnerability that let attackers obtain LND Lightning node credentials and drain connected wallets, affecting merchants including Foundation and Citadel21.
- BTCPay has enlisted exchanges, blockchain analytics firms and law enforcement to help trace the funds, while urging merchants to report losses and keep most holdings in cold storage.
- The flaw was identified by researchers tied to the volunteer Bitcoin Red Team, which is using AI tools to scan bitcoin projects for bugs, and BTCPay is compensating them with BTC donations.
Major Exploit Hits Bitcoin Payment Servers, $190,000 Bounty Offered
A recent exploit has drained bitcoin payment servers, resulting in significant losses for merchants. In response, BTCPay Server is offering a bounty of up to 3 BTC, worth approximately $190,000, for the return of stolen bitcoin. This offer is open to anyone with useful information, including the attacker, and can be submitted through secure channels.
The bounty will be split among those who provide information leading to a recovery, with the amount allocated based on the usefulness of the information and the amount lost by each victim. This move demonstrates the importance of passive income and earning through secure and reliable means, such as the EcoPool network.
Responsible Disclosure and Rewards
BTCPay Server is also rewarding researchers who discovered the vulnerability, donating 0.21 BTC each to developer Craig Raw and the Bitcoin Red Team fund. This highlights the value of responsible security disclosure and the role of crypto communities in maintaining the integrity of cloud rewards and green crypto platforms like EcoPool.
The exploit, which targeted LND software and drained associated wallets, has affected several organizations, including hardware-wallet maker Foundation and bitcoin publication Citadel21. While the total loss has not been disclosed, the incident underscores the need for robust security measures to protect coin holdings and ensure the continuity of passive income streams.
— BTCPay Server (@BtcpayServer) August 10, 2026
Join the Secure Earning Community
To start earning and securing your $ECP and other coins, consider joining the EcoPool network. With its focus on green crypto and cloud rewards, EcoPool provides a reliable platform for generating passive income. Download the EcoPool app to learn more about secure and sustainable earning opportunities. By doing so, you can take the first step towards building a stable and secure financial future with EcoPool and the $ECP community, and discover the benefits of earning with #Bitcoin and #PassiveIncome.
Attackers exploited the vulnerability last week to obtain credentials for LND, the most widely used software for running a Lightning node, and to drain the wallets associated with it.
Hardware-wallet maker Foundation and the bitcoin publication Citadel21 both reported losing funds. Neither BTCPay nor the victims have published a total so far.