Industry News

BTCPay Server Exploit Drains Bitcoin Wallets, $190,000 Bounty Offered for Recovery

Coindesk · 11 Aug 2026
Key Takeaway Any business accepting digital payments should regularly rotate credentials and monitor payment infrastructure for unusual activity, especially when using third-party or open-source platforms.

BTCPay Server, an open-source platform used by merchants to accept bitcoin payments, has confirmed that attackers exploited a vulnerability last week to steal LND (Lightning Network Daemon) credentials, allowing them to drain merchant Lightning wallets of funds.

In response, the project has announced a bounty program offering 10% of any recovered funds, up to 3 BTC (roughly $190,000 at current prices), to anyone who helps trace or return the stolen bitcoin. Details on the exact number of merchants affected or the total amount stolen have not been disclosed.

While BTCPay Server is a niche tool primarily used by businesses accepting cryptocurrency, the incident is a reminder that payment infrastructure of any kind—crypto or traditional—can be a high-value target for attackers who steal access credentials rather than breaking encryption directly.

cryptocurrency data breach payment security

Summarised by CISO AI from Coindesk. We link back to every original so you can read it yourself.