The developers of BTCPay Server have established a reward for assistance in refunding funds
8/11/2026, 09:08 AM • Евгения Слив

The BTCPay Server payment server has announced a reward for assistance in asset recovery. The attackers withdrew funds through a vulnerability in the program on Lightning nodes. The reward will be ten percent of the refunded amount without additional conditions. The maximum payout amount is limited to three bitcoins with a full refund. Unnamed sponsors and partners of the project volunteered to finance this payment. In the official publication, they were described as friends and supporters of the server. Anyone who is able to return the coins was offered to contact with the information. This person may even be the attacker himself or his representative. With the participation of several informants, the reward will be divided between them. This section takes into account the scale of the damage and the practical significance of the information. The payment takes place after the actual refund of funds to the wallets of the victims.
The BTCPay Server Foundation will send separate payments to developers for vulnerability disclosure. Sparrow Wallet developer Craig Rowe will receive twenty-one hundredth of bitcoin. A similar amount will go to the fund of the Bitcoin Red Team volunteer group. The representatives of the project explained the modest amounts by their non-commercial status of the FOSS project. The team recommended that affected users contact local law enforcement agencies. It is also worth reporting the theft to the services that accept stolen coins. Exchange security services and analysts offered assistance in the investigation. The developers have so far refused to disclose the scale of the incident. The exact amount of losses and the number of affected nodes remain unknown. The team promised to publish a full technical analysis of the incident later. The attack affected only bundles with LND without damaging on-chain wallets. The public access to the LND API has been temporarily disabled in the program version. Zeus external wallets are not yet connected via the server domain. API access will be returned only after a thorough security check.
The team is currently focused on developing patches and strengthening the code review. They plan to involve external independent security auditors to check the code. The developers are studying the reports of the Bitcoin Red Team and research groups. Reports from Project Loupe and Magic Grants are also being studied. Materials from independent security researchers of blockchain systems are involved. Users were advised to keep their fixed assets in cold wallets. The change in approach in the project was associated with the spread of AI technologies. The models make vulnerability detection faster and cheaper than before. Many software platforms are becoming a target for modern attackers. Experts believe that the same reality awaits the entire industry. Artificial intelligence shifts the balance of power in favor of the attackers. Models become smarter and find holes in the code faster. Bitcoin projects remain a notable target for such attacks. The rest of the software cannot escape a similar fate either. In August, the Coldcard hardware wallet was hacked. Charles Guillemet, Technical Director of Ledger, spoke about this situation. He stated the need to review randomness generators in devices.
***
The material has been prepared solely for informational purposes and does not constitute financial advice or recommendation.
