Crypto news

11.08.2026
09:46

BTCPay Server offers a reward of up to 3 BTC for the return of stolen funds following the hacking of Lightning nodes.

хакеры hackers, перемещение средств

On August 10, the BTCPay Server payment server officially announced a bounty program for assistance in recovering assets stolen by attackers from Lightning nodes through a critical vulnerability in the software. This is a rare step for a FOSS project, demonstrating the seriousness of the incident and the team's readiness to take unconventional measures.

The reward will amount to 10% of the recovered funds, but will not exceed 3 BTC (~$190,000), provided that the damage is fully compensated. The funding for the payouts was taken on by anonymous sponsors and project partners, referred to in the official statement as "friends and supporters" of BTCPay Server. This underscores that even in a decentralized ecosystem, the community is willing to consolidate to protect shared interests.

Anyone with information that could lead to the return of the coins is invited to participate, including the attacker themselves. In the case of multiple claims, the reward will be distributed proportionally to each participant's contribution, taking into account the scale of damage to affected parties and the practical value of the data provided. This approach minimizes the risks of conflicts and encourages collective action.

In parallel, the BTCPay Server Foundation will allocate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team for "responsible disclosure of the vulnerability." The project acknowledged the modesty of these amounts, explaining it by BTCPay's non-commercial status as free and open-source software. However, the symbolic gesture here matters more than the financial one: it sets a standard for ethical bug hunting in the industry.

Affected users are advised to immediately contact local law enforcement agencies, as well as services to which the stolen funds may have been directed. According to the developers, security services of major exchanges, blockchain analytics companies, and government representatives have already offered support. This indicates that the incident may have broader resonance than it seems at first glance.

The scale of the attack has not yet been disclosed: neither the exact amount of losses nor the number of affected nodes. The team promises to publish a full technical breakdown later. It is known that the vulnerability only affected setups with LND, while on-chain wallets remained untouched. In version 2.4.2, public access to the LND API on Docker builds has been temporarily disabled, which limits the connection of external wallets like Zeus via the BTCPay domain or onion address — access will be restored after the security review is completed.

Currently, the team is focused on patches and strengthening code review with the involvement of external auditors, studying reports from Bitcoin Red Team, Project Loupe, Magic Grants, and independent researchers. Users are strongly advised to keep funds in cold wallets.

Particular attention deserves BTCPay's stance on the role of artificial intelligence in the escalation of threats. The developers directly state: "AI shifts the balance of power in favor of attackers. Models are becoming smarter, and finding holes in large codebases is now cheaper and faster. Bitcoin projects are the most tempting target, but other software will not escape the same fate." This is a timely warning for the entire software development industry.

My analysis: This incident is not just another hack, but an alarming signal of systemic vulnerability to AI-driven attacks. BTCPay chose the right strategy: transparency, collaboration with the community, and incentivizing the return of funds through a reward. However, the main lesson here is that preventive security must become priority #1 for all Bitcoin projects, otherwise we will see a repetition of similar scenarios on a much larger scale.