BTCPay Server announces a bounty of up to 3 BTC for the return of stolen funds: incident details and implications for the industry

On August 10, the BTCPay Server payment platform officially announced a bounty program for those who help recover assets stolen from Lightning nodes as a result of a recent critical vulnerability. The reward is set at 10% of the recovered amount, but with a strict cap of 3 BTC (~$190,000), provided that the full damage is compensated. Funding is provided by anonymous sponsors and project partners, referred to in the official statement as "friends and supporters" of BTCPay Server.
Key point: the offer is addressed not only to third-party specialists, but also to the attacker themselves. If multiple parties participate in the recovery of funds, the reward will be distributed proportionally to their contribution—taking into account the scale of damage to each victim, the share of recovered coins, and the practical value of the information provided. This approach demonstrates the team's flexibility, but at the same time underscores the seriousness of the situation: the project is ready to negotiate even with hackers.
In addition to the main reward, the BTCPay Server Foundation will allocate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team for responsible disclosure of the vulnerability. The amounts are modest, and the project acknowledges this, explaining it by BTCPay's non-commercial status as a FOSS initiative. However, for the community, this is an important signal: even under a limited budget, the ethics of responsible disclosure must be rewarded.
The scale of the incident has not yet been disclosed—neither the exact amount of losses nor the number of affected nodes. The team promises to publish a full technical breakdown later. It is only known that the attack affected exclusively LND setups, while on-chain wallets remained untouched. In version 2.4.2, public access to the LND API on Docker builds has been temporarily disabled: external wallets like Zeus cannot connect via the BTCPay domain or onion address until the security review is completed.
Currently, the team is focused on patches and strengthening code review with the involvement of external auditors. Reports from Bitcoin Red Team, Project Loupe, Magic Grants, and independent researchers are being studied. Victims are advised to contact local law enforcement and services where the stolen coins may have been sent. Assistance has already been offered by exchange security services, blockchain analytics firms, and authorities.
Notably, BTCPay links the rise of such attacks to the spread of AI. Models make finding vulnerabilities in large codebases faster and cheaper, shifting the balance of power in favor of attackers. "Bitcoin projects are the most tempting target, but other software will not escape the same fate," the developers note. This is not just an excuse, but a real trend: automated hacking is becoming widespread, and the industry will have to rethink its approaches to security.
My analytical conclusion
The BTCPay incident is another reminder that even mature open-source projects are vulnerable, and the Lightning Network, despite its innovativeness, remains a complex and risky infrastructure. The 3 BTC reward is not so much an attempt to recover funds as a PR move to restore community trust. However, the main lesson here is broader: with the growing capabilities of AI, code security must become the number one priority for all Bitcoin projects, otherwise we will see a wave of similar exploits.