BTCPay Server Offers Bounty for Stolen Bitcoin Following Exploit
BTCPay Server supporters have offered a bounty for the return of Bitcoin stolen in a recent exploit. The reward amounts to 10% of recovered funds, with a cap of 3 BTC, which is approximately $190,000. This offer extends to anyone who can provide information leading to the recovery of the stolen cryptocurrency, including the attackers themselves.
Details of the Exploit and Recognition of Security Researchers
BTCPay initially alerted users to the attacks and advised immediate updates to version 2.4.2 or taking servers offline. The exploit enabled attackers to acquire LND admin macaroons, which are credentials providing extensive control over a Lightning Network node. These credentials were then used to access connected wallets. The Lightning Network functions as a layer-2 payment solution on the Bitcoin blockchain, facilitating quicker and more economical transactions.
While the total amount of stolen Bitcoin and the number of affected users remain undisclosed, the BTCPay Server Foundation plans to donate 0.21 BTC each to security researcher Craig Raw and the Bitcoin Red Team fund. This recognition is for their responsible disclosure of the vulnerability. The project acknowledged these contributions as a means of appreciating critical security work that benefits the entire ecosystem.
BTCPay Server's Commitment to Enhanced Security
BTCPay stated its commitment to strengthening code reviews and prioritizing security patches over new features. This shift in focus is a response to the increasing ease with which artificial intelligence can assist attackers in identifying vulnerabilities within Bitcoin software. The organization indicated that defending software in the current environment necessitates improved tools, more comprehensive reviews, faster security responses, and support for researchers who responsibly report vulnerabilities.