BTCPay Server users running versions prior to 2.4.2 are sitting on a live vulnerability—one that exposed Lightning Network Daemon (LND) wallet credentials, including seed phrases and private keys. Supporters are offering a recovery bounty of up to three Bitcoin for affected funds.

The exploit targets self-hosted payment processors directly. Any Lightning Network funds managed through unpatched BTCPay Server instances are exposed to unauthorized withdrawal. Attackers can drain channels and move Bitcoin off-chain. For anyone holding liquidity in Lightning channels on an older instance, the risk is immediate. Update to version 2.4.2 or later now.

The recovery bounty is capped at three BTC—approximately $191,769 at current prices, with BTC trading at $63,923. The incentive is designed to encourage ethical return of compromised funds rather than punitive action. Post-exploit bounties are a standard tool in crypto for clawing back losses after a vulnerability surfaces.

BTCPay Server is non-custodial, which means the security burden falls entirely on the operator. This exploit is a direct reminder that self-custody infrastructure requires active maintenance—open-source and community-driven does not mean set-and-forget. Continuous auditing and rapid patch deployment are non-negotiable for anyone running their own Lightning node or payment processor.

The BTCPay Server team is actively monitoring for further exploits and supporting affected users. Detailed update instructions and security advisories are on the project's official GitHub repository. The community is waiting on final figures for total funds compromised and any confirmed bounty claims.