Crypto news

11.08.2026
10:33

BTCPay Server is offering a reward of up to 3 BTC for the return of stolen funds following an attack on Lightning nodes.

хакеры hackers, перемещение средств

On August 10, the BTCPay Server team officially announced the launch of a bounty program for assistance in recovering assets stolen in a recent attack on Lightning nodes. The incident, which affected the payment infrastructure, forced developers to take an unconventional step—offering a reward of 10% of the recovered amount, but no more than 3 BTC (~$190,000) upon full restoration of funds.

Funding for this initiative was taken on by anonymous sponsors and partners of the project, referred to in the official statement as "friends and supporters" of BTCPay Server. Notably, the offer extends to anyone with information that could lead to the return of the coins, including the attackers themselves. If multiple individuals are involved in the recovery process, the reward will be distributed proportionally to their contribution and the practical significance of the data provided, taking into account the scale of damage to each victim.

Incident Details and Community Reaction

Separately, the BTCPay Server Foundation allocated 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team for "responsible disclosure of the vulnerability." The project acknowledged that the amounts may seem modest but emphasized BTCPay's non-commercial status as a FOSS project, which limits financial capabilities.

The scale of the attack has not yet been disclosed: neither the exact amount of losses nor the number of affected nodes has been made public. The team promises to publish a full technical breakdown of the incident later. It is known that the attack affected exclusively LND setups, while on-chain wallets remained untouched. In version 2.4.2, public access to the LND API on Docker builds has been temporarily disabled, limiting the connection of external wallets such as Zeus via the BTCPay domain or onion address.

Developers have focused on patches and strengthening code review with the involvement of external auditors. In particular, reports from Bitcoin Red Team, Project Loupe, Magic Grants, and independent researchers are being studied. Users are strongly advised to store funds in cold wallets until the vulnerability is fully resolved.

AI as a New Threat Factor

The project links the change in security approach to the proliferation of artificial intelligence. In their view, AI models make vulnerability discovery faster and cheaper, turning many platforms into easy targets. "Artificial intelligence shifts the balance of power: attackers gain an advantage. Models are getting smarter, and finding holes in large codebases is now cheaper and faster. Bitcoin projects are the most tempting target, but other software will not escape the same fate," the official statement reads.

Victims are advised to contact local law enforcement agencies and services where the stolen coins may have been transferred. Assistance has already been offered by exchange security services, blockchain analytics firms, and government representatives.

My comment: The situation with BTCPay Server is a warning sign for the entire industry. The fact that even trusted FOSS projects fall victim to targeted attacks underscores the need to rethink security standards. AI is indeed changing the rules of the game, and projects will have to invest significantly more resources in defense than before. The 3 BTC reward is a reasonable compromise, but it is unlikely to compensate for reputational losses and damage to user trust.