Crypto news

11.08.2026
09:11

BTCPay Server Offers a Reward of Up to 3 BTC for the Return of Stolen Funds

хакеры hackers, перемещение средств

The BTCPay Server payment platform has officially announced a bounty program for those who help recover assets stolen during a recent attack on Lightning nodes. The incident, which exposed a critical vulnerability in the code, forced the team to take unconventional measures.

Terms and Scope of the Reward

According to my analysis, the bonus mechanics are as follows: the payout will be 10% of the recovered funds, but with a hard cap of 3 BTC (approximately $190,000). Notably, the funding is provided not by the developers themselves, but by anonymous "friends and supporters" of the project. This underscores how severe the blow to reputation and infrastructure has been.

Anyone with any information that could lead to the recovery of the coins is invited to participate — including the attackers themselves. In the case of a collective contribution, the reward will be divided proportionally based on the significance of the data and the volume of recovered funds, as agreed with the affected parties.

Additional Payments and Community Reaction

In addition to the main reward, the BTCPay Server Foundation fund will allocate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team. These funds are a token of appreciation for the "responsible disclosure" of the vulnerability. The amounts are modest, but this is a deliberate step, given BTCPay's non-commercial status as a FOSS project.

Technical Details and Consequences

It is important to emphasize: the attack affected exclusively LND setups, while on-chain wallets remained untouched. In version 2.4.2, public access to the LND API on Docker builds has already been disabled. External wallets, such as Zeus, will temporarily be unable to connect via the BTCPay domain or onion address — access will only be restored after a full security review.

The team is currently focused on patches and strengthening code review with the involvement of external auditors. They are studying reports from Bitcoin Red Team, Project Loupe, and Magic Grants. The scale of losses and the number of affected nodes have not yet been disclosed, which raises questions within the community. A full breakdown of the incident is promised to be published later.

My Expert Perspective

The BTCPay situation is a wake-up call for the entire industry. Developers rightly link the rise in attacks to AI, which radically reduces the cost of finding vulnerabilities. However, in my view, relying on crowdsourcing and rewards is a stopgap measure. It is critically important that projects rethink their security models at the architecture stage, rather than reacting after the fact. Otherwise, we will see similar incidents repeat with alarming regularity.