Crypto news

11.08.2026
11:04

BTCPay Server offers a reward of up to 3 BTC for the return of stolen funds following the compromise of Lightning nodes.

хакеры hackers, перемещение средств

On August 10, the BTCPay Server payment server officially announced the launch of a reward program for assistance in recovering assets stolen in a recent attack on Lightning nodes. The incident, which affected users of LND connections, was a serious blow to the project's reputation, and now the team is trying to turn the situation around by offering a substantial reward for effective assistance.

Terms and Scope of the Reward

According to my analysis, the payment mechanics are as follows: the reward will be 10% of the recovered amount, but with a hard cap of 3 BTC (about $190,000) provided the stolen funds are fully recovered. Funding for this initiative was taken on by unnamed sponsors and partners of the project, who were delicately referred to in the official announcement as "friends and supporters" of BTCPay Server. Anyone with information that could lead to the recovery of the coins is invited to come forward, including the attacker themselves. If several people contribute to the investigation, the reward will be divided among them proportionally—in agreement with the victims, based on the scale of the damage and the practical significance of the data provided.

Gratitude to Researchers and Current Measures

In parallel, the BTCPay Server Foundation has decided to allocate 0.21 BTC each to Sparrow Wallet developer Craig Raw and the volunteer group Bitcoin Red Team for "responsible disclosure of the vulnerability." The project acknowledges that the amounts are quite modest but explains this by BTCPay's non-commercial status as a FOSS project (free and open-source software). At this point, the team has not disclosed either the total amount of losses or the number of affected nodes—a full technical breakdown of the incident is promised to be published later. It is known that the attack affected exclusively LND connections, while on-chain wallets remained secure. In version 2.4.2, public access to the LND API on Docker builds has already been temporarily disabled to prevent further intrusions.

AI as a New Threat Factor

The developers also emphasize a fundamental shift in the balance of power between defense and attack. In their view, the proliferation of artificial intelligence radically cheapens and accelerates the search for vulnerabilities in large codebases. "Artificial intelligence shifts the balance of power: attackers gain the advantage. Bitcoin projects are the most tempting target, but other software will not escape the same fate," the official statement stresses. Users are strongly advised to store funds in cold wallets.

My comment: The situation with BTCPay Server is a wake-up call for the entire ecosystem. The fact that even time-tested FOSS projects are falling victim to attacks indicates the need to reconsider security standards in the industry. Engaging external auditors and bug bounty programs is the right step, but it must become the norm, not an emergency measure. In an era when AI arms attackers, only a proactive approach to security can save user funds.