Timeline
- 8.5
Harmony Bridge Hack and BTCPay Vulnerability Exposed in Security Roundup
A new security roundup highlights two incidents: the June 2022 Harmony Horizon Bridge hack that lost about $100 million, and an actively exploited critical vulnerability in BTCPay Server that can drain Lightning Network node funds. These incidents underscore persistent weaknesses in cross-chain bridge design and payment server security, putting user funds at risk and increasing regulatory and community scrutiny on crypto infrastructure. The Harmony bridge was protected by a 2-of-5 multisig scheme, and attackers stole two private keys to approve malicious transactions; the FBI attributed the attack to North Korea's Lazarus Group. BTCPay Server, an open-source Bitcoin payment processor, issued an emergency patch for the actively exploited vulnerability.
- 8.5
Security Roundup Covers Harmony Bridge Hack and BTCPay Server Flaws
A security roundup covers two major incidents: the Harmony Horizon bridge exploit that lost roughly $100 million in June 2022, and a critical BTCPay Server vulnerability that let attackers drain funds from Lightning nodes running LND. The roundup underscores persistent risks in cross-chain bridges and Bitcoin payment infrastructure, where a single exploit can directly compromise user funds. It affects DeFi users, bridge operators, and merchants relying on Lightning payments, and may heighten security scrutiny across crypto infrastructure. For Harmony, the attacker appears to have taken control of the multisig contract behind the bridge, affecting roughly 64,000 wallets. For BTCPay Server, the vulnerability exposed LND Lightning node credentials, and operators were urged to update to version 2.4.2 or take servers offline.
- 7.5
BTCPay Server Offers Bitcoin Bounty After Lightning Wallet Exploit
BTCPay Server announced a 10% bounty (capped at 3 BTC) for recovery of Bitcoin stolen in an exploit that abused LND admin macaroons, and is urging all users to update to version 2.4.2 immediately. The incident exposes real security risks in self-hosted Lightning Network infrastructure and directly affects operators who run vulnerable BTCPay/LND servers. It also underscores how open-source payment processors must prioritize rapid patching and rewarded vulnerability research to protect user funds. Attackers obtained LND admin macaroons, credentials that grant broad control over a Lightning node, and used them to access connected wallets. BTCPay has not disclosed how much Bitcoin was stolen or how many users were affected, and the bounty will be split among verified tips; the BTCPay Server Foundation is also donating 0.21 BTC each to researcher Craig Raw and the Bitcoin Red Team.
- 8.0
BTCPay Server Supporters Offer Up to 3 BTC Bounty After Critical Exploit
BTCPay Server acknowledged a critical exploit that may have been AI-assisted, and credited Craig Raw and the Bitcoin Red Team fund for reporting the issue. Supporters have pledged up to 3 BTC as a recovery bounty. BTCPay Server is a widely used self-hosted Bitcoin payment processor, so a critical exploit could affect merchants and users who rely on it to accept Bitcoin directly. This incident also highlights the growing role of AI both in attacking and in defending open-source cryptocurrency infrastructure. Supporters have pledged up to 3 BTC as a recovery bounty, while BTCPay Server said the exploit may have been AI-assisted. The project credited Craig Raw and the Bitcoin Red Team fund for reporting the vulnerability.