On Monday, Bitcoin was largely flat, hovering around $64,000; meanwhile, backers of BTCPay Server pledged a bounty of up to 3 $BTC for the return of stolen funds resulting from a critical vulnerability in the open-source payment software.
The lack of enthusiasm suggests traders likely view this event as a threat to merchants and Lightning users, but not to Bitcoin itself. Bitcoin's market cap was estimated at $1.28 trillion, having fallen roughly half a percent according to CoinMarketCap. The hack affected software built on top of Bitcoin, not the core network.
Prices Held Steady While Some Lightning Nodes Were Drained
On August 7, BTCPay Server disclosed the vulnerability and urged users to upgrade to version 2.4.2 or stop their servers until the issue was fixed. Among users reporting attacks on their Lightning nodes were Foundation and Citadel21. However, BTCPay did not provide information on the total scale of the damage or the number of affected nodes.
The project stated that their own blockchain wallets, including hot wallets, were not affected. Instead, attackers could obtain LND administrator (macaroon) credentials from vulnerable BTCPay instances and use them to manage connected Lightning wallets.
Backers Contribute 10% of Any Recovered Profit
To help victims recover their funds, BTCPay backers pledged to pay a reward of 10% of any recovered stolen amount, but no more than 3 $BTC if the entire sum is returned.
The BTCPay Server Foundation is also donating 0.21 $BTC each to security researcher Craig Rowe and the Bitcoin Red Team for discovering and privately reporting the vulnerability. Rowe, developer of the Sparrow Wallet, stated that he was also among those affected.
What Does the Macaroon-Related Vulnerability Allow Attackers to Do?
All versions of the BTCPay Server prior to 2.4.2 are vulnerable to the LND macaroon credential issue. The company has not publicly assigned an identifier (CVE) to this specific issue.
A macaroon is a type of authentication credential used by LND to authorize API access. The vulnerability allowed attackers to obtain the LND administrator macaroon from a compromised server, giving them control over the associated Lightning node and wallets.
The update mechanism should be accessible via the Admin Panel → Server → Maintenance → Update, where operators can check if version 2.4.2 is displayed in the footer. If they cannot perform the update immediately, BTCPay recommends turning off the server.
Simply applying patches may not be enough. Operators need to update their Lightning credentials and Macaroon files, as stolen credentials may remain valid. According to LND documentation, deleting Macaroon files does not invalidate previously issued credentials — the Macaroon database must also be replaced.
Version 2.4.2 also fixed a separate TOTP two-factor authentication bypass bug via Greenfield basic authentication, reported on August 4. However, this situation is unrelated to the LND vulnerability currently being exploited by attackers.
Why the Surrounding Software is a Weak Point
This issue is largely infrastructural, as the defect in question resides at the application layer of BTCPay, not the consensus rules or cryptography underlying Bitcoin. As a result, Bitcoin continued to operate without any issues.
A significant amount of data remains available. BuiltWith indicates that 248 websites have used BTCPay Server at various times, including 74 active websites, though these measurements do not include private installations.
Meanwhile, according to 1ML, there are about 5,585 active Lightning nodes, with a total of approximately 2,640 $BTC available in them. River claims that Bitcoin merchant usage has increased by 74% towards 2025, and monthly Lightning network transactions will exceed $1 billion.
Artificial Intelligence on Both Sides of the Exploit
BTCPay stated that the incident highlights how AI is changing software security. Better code analysis with AI can help defenders find vulnerabilities faster, while also lowering attackers' costs for studying large open-source codebases.
This issue is not limited to payment software. A recent Coldcard data leak led to the theft of approximately 1,816 $BTC from over 5,200 addresses, and the fallout extended beyond the stolen funds, as the company temporarily altered its data handling practices.
Chainalysis has also warned that AI-assisted analysis and simplified smart contract tools could make it easier to scale attacks on poorly audited code.
For Bitcoin's infrastructure, the lesson extends beyond any single bug: AI can accelerate vulnerability discovery, but successful attacks can have consequences far beyond the compromised code, from emptying wallets and disrupting payments to investigations and changes in how companies handle customer data.







