Crypto news

11.08.2026
10:48

BTCPay Server offers a reward of up to 3 BTC for the return of stolen funds following the hacking of Lightning nodes.

хакеры hackers, перемещение средств

On August 10, BTCPay Server officially announced the launch of a reward program for assistance in recovering assets stolen by attackers from Lightning nodes through a critical vulnerability in the software. The reward is 10% of the recovered amount, but with a strict cap — a maximum of 3 BTC (about $190,000) for a full return of funds. Funding is provided by anonymous sponsors and project partners, whom the team delicately calls "friends and supporters" of BTCPay Server.

Terms and details of the reward

The offer is addressed to anyone with information that could lead to the return of the coins, including the hackers themselves. If multiple people are involved in a successful operation, the payment will be distributed proportionally to their contribution, taking into account the scale of damage to each victim and the practical value of the data provided. This is a sensible approach that encourages cooperation even within attacker groups — a classic "bounty for betrayal" mechanism.

In parallel, the BTCPay Server Foundation allocated 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team for "responsible disclosure of the vulnerability." The amounts are modest, but the project emphasizes: as a non-profit FOSS project, it cannot afford generous bug bounties like large corporations.

Scale of the incident and reaction

The team has still not disclosed either the total amount of losses or the number of affected nodes — a full technical breakdown is promised to be published later. It is known that the attack affected exclusively LND setups, while on-chain wallets remained untouched. In version 2.4.2, public access to the LND API on Docker builds has already been disabled, which is why external wallets like Zeus temporarily cannot connect via the BTCPay domain or onion address.

Victims are recommended to immediately contact law enforcement agencies and services that may have received the stolen funds. The developers note that they have already received assistance from exchange security teams, blockchain analysts, and government agencies.

The AI threat and the future of security

BTCPay links the rise in attacks to the spread of artificial intelligence. Models make finding vulnerabilities in large codebases faster and cheaper, shifting the balance of power in favor of attackers. "Bitcoin projects are the most tempting target, but other software will not escape the same fate," the project warns. This is an alarming signal for the entire industry: traditional audit methods can no longer keep pace with the speed of automated attacks.

My analysis: The situation with BTCPay is a vivid example of a new reality where AI tools turn vulnerability hunting into an industry with a low entry barrier. The 3 BTC payout is not just an attempt to recover funds, but also a strategic move: the project is trying to seize the initiative from hackers by creating an economic incentive for "white hat" researchers. However, until the team discloses the scale of losses, user trust in the Lightning infrastructure remains in question. The incident once again confirms: even the most mature open-source projects are vulnerable, and cold storage remains the gold standard.