BTCPay is putting up a $190,000 bounty after a security exploit last week drained merchant Lightning wallets. The attackers got hold of LND credentials and used them to empty the wallets. The bounty is set at 10% of recovered funds, capped at 3 BTC.
How the exploit worked
The breach targeted LND, the software that runs Lightning Network nodes. With the stolen credentials, the attackers could access merchant wallets and move funds out. BTCPay hasn't said how many merchants were hit or how much was taken in total.
The company moved quickly to announce the bounty. It's a direct appeal to anyone who can help track down the stolen funds or identify the attackers. The 10% cut is meant to incentivize action, not just good intentions.
The bounty terms
BTCPay is offering up to 3 BTC, which is roughly $190,000 at current prices. That's the maximum payout. The actual reward depends on how much of the stolen money gets recovered. If only a fraction comes back, the bounty shrinks accordingly.
This isn't a flat reward. It's a percentage of what's recovered. So the more funds that get returned, the bigger the payout. BTCPay likely hopes this structure pushes people to dig deeper and act faster.
What merchants should do now
Merchants who run Lightning wallets on BTCPay should check their LND credentials and look for any unusual activity. The exploit happened last week, so any suspicious transactions from that window are worth reviewing. BTCPay hasn't released a patch or a fix yet, but the bounty suggests they're taking the incident seriously.
For now, the company is focused on recovery. The bounty is open, and the clock is ticking. Whether the attackers get caught or the funds get returned is still an open question. BTCPay's next move will likely depend on what the bounty hunt turns up.




