Crypto news

11.08.2026
09:31

BTCPay Server Has Offered a Reward of up to 3 BTC for the Return of Stolen Funds

хакеры hackers, перемещение средств

On August 10, the BTCPay Server payment server announced a reward for help in recovering assets that attackers withdrew from Lightning nodes through a vulnerability in the software. This is not just a goodwill gesture, but a strategic move aimed at restoring trust in the project after a serious incident.

Reward terms and community reaction

The reward will be 10% of the recovered amount, but no more than 3 BTC (~$190,000) if the stolen funds are fully recovered. Unnamed sponsors and partners of the project volunteered to finance the payment—described in the publication as "friends and supporters" of BTCPay Server. Anyone with information that could lead to the return of the coins was invited to come forward, including the attacker themselves. If several people contribute to the recovery, the reward will be divided among them in agreement with the victims—based on the scale of each person's losses, the share of recovered funds, and the practical significance of the information provided.

Separately, the BTCPay Server Foundation will send 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team for "responsible disclosure of the vulnerability." The project acknowledged that the amounts are modest but explained this by BTCPay's non-commercial status as a FOSS project. This is an important signal: even in a critical situation, the project remains true to its open-source principles, although, in my view, such payments could have been more substantial to incentivize security.

Scope of the incident and technical details

The scope of the BTCPay incident has still not been disclosed: neither the amount of losses nor the number of affected nodes. The team promised to publish a full analysis of what happened later. The developers clarified that the attack only affected setups with LND, and on-chain wallets were not impacted. In version 2.4.2, public access to the LND API on Docker builds was temporarily disabled—external wallets like Zeus cannot yet connect via the BTCPay domain or onion address, and access will be restored after a security review.

Currently, the team is focused on patches and strengthening code review with the involvement of external auditors, studying reports from Bitcoin Red Team, Project Loupe, Magic Grants, and independent researchers. Users were advised to keep funds in cold wallets. The change in the project's approach was linked to the spread of AI: models make vulnerability discovery faster and cheaper, causing many platforms to become easy targets. According to specialists, the same reality awaits the entire software development industry.

"Artificial intelligence shifts the balance of power: attackers gain the advantage. Models are becoming smarter, and finding holes in large codebases is now cheaper and faster. Bitcoin projects are the most tempting target, but other software will not escape the same fate," the BTCPay post states.

Let me remind you that in August, amid the Coldcard hack, Ledger CTO Charles Guillemet stated the need to review random number generator verification in bitcoin storage devices.

My analysis: The situation with BTCPay Server is a wake-up call for the entire ecosystem. A vulnerability in a popular FOSS project, exploited via Lightning, shows that even "gold standard" security is not immune to attacks. However, the quick response, transparency, and willingness to pay for the return of funds is the right approach that could set an example for other projects. In the long term, I expect a stronger role for external audits and bug bounty programs in the industry, especially in light of AI's growing capabilities for vulnerability discovery.