Supporters of BTCPay Server, the open-source bitcoin payments processor that recently disclosed an exploit, have committed to supporting a recovery bounty of 10% of any funds recovered, capped at 3 BTC for full recovery, according to an announcement on Monday.

BTCPay Server announced on Friday that a critical vulnerability was being actively exploited and urged users to update their servers to version 2.4.2.

In a security advisory, the firm noted that all BTCPay versions “prior to 2.4.2, including 2.4.2 release candidates” were vulnerable to the attack. “The vulnerability allowed an attacker to obtain LND admin macaroon credentials from affected instances and use them to access connected LND wallets,” the project wrote on X.

In other words, a security flaw let attackers steal the master access keys from certain Bitcoin payment servers, giving them full control over any linked Lightning wallets.

A Lightning macaroon is a digital authentication token and credential file used by bitcoin nodes. “Users of other Lightning implementations and users who do not use Lightning do not need to update to address this LND credential risk, but we strongly encourage them to update BTCPay Server,” BTCPay said.