Crypto news

11.08.2026
10:01

BTCPay Server is offering a reward of up to 3 BTC for the return of stolen funds following an attack on Lightning nodes.

хакеры hackers, перемещение средств

On August 10, the BTCPay Server team officially announced a bounty program aimed at recovering assets stolen from Lightning nodes by attackers through a critical vulnerability in the software. This is an unprecedented step for a non-profit project, highlighting the severity of the incident and the commitment to restoring community trust.

Terms and Mechanism of the Reward

According to my analysis, the payment structure is as follows: the reward will be 10% of the recovered amount, but its maximum size is capped at 3 BTC — approximately $190,000 at the time of publication. Notably, the payment is guaranteed only upon full reimbursement of the stolen coins. Funding is provided by anonymous sponsors and project partners, referred to in the official statement as "friends and supporters" of BTCPay Server.

An important nuance: the offer is addressed to anyone with information that could lead to the recovery of funds, including the attacker themselves. If several people contribute to resolving the situation, the reward will be distributed among them proportionally. Evaluation criteria include the scale of damage to each victim, the share of recovered funds, and the practical significance of the information provided.

Additional Payments and Ecosystem Reaction

In addition to the main reward, the BTCPay Server Foundation allocated 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team. These funds are recognition of their "responsible disclosure of the vulnerability." The project honestly admitted that the amounts may seem modest, but this is due to BTCPay's non-profit status as a FOSS project.

In my assessment, this step demonstrates maturity of approach: the team is not only trying to minimize damage but is also actively building relationships with security researchers, which is critically important in the current environment.

Technical Details and Recommendations

The developers clarified that the attack affected exclusively LND setups, while on-chain wallets remained untouched. In version 2.4.2, public access to the LND API on Docker builds has been temporarily disabled — this means that external wallets such as Zeus cannot yet connect via the BTCPay domain or onion address. Access will only be restored after a full security review.

Victims are strongly advised to contact local law enforcement agencies and services that may have received the stolen coins. Notably, assistance has already been offered by exchange security teams, blockchain analytics firms, and government agencies. However, the scale of the incident — the amount of losses and the number of affected nodes — has still not been disclosed, with a full analysis promised for later publication.

Expert Perspective on the Future

The team is focused on patches and strengthening code review with the involvement of external auditors, studying reports from Bitcoin Red Team, Project Loupe, and Magic Grants. Users are advised to keep funds in cold wallets. The project links the change in approach to the spread of AI: models make vulnerability discovery faster and cheaper, turning many platforms into easy targets.

"Artificial intelligence shifts the balance of power: attackers gain the advantage. Models are becoming smarter, and finding holes in large codebases is now cheaper and faster. Bitcoin projects are the most tempting target, but other software will not escape the same fate," the BTCPay statement emphasizes.

Against the backdrop of the recent Coldcard hack, Ledger CTO Charles Guillemet has already stated the need to review the verification of random number generators in bitcoin storage devices. This confirms my long-standing position: the industry is entering a phase where proactive security is becoming not a luxury but the only way to survive. BTCPay, by offering a reward and acknowledging the role of researchers, sets the right tone, but the market will need far more systemic changes to counter AI-driven attacks.