On August 10, BTCPay Server announced a reward aimed at recovering assets that were stolen from Lightning nodes due to a vulnerability in their software.
The reward will be set at 10% of the recovered amount, capped at 3 BTC (approximately $190,000) if the full amount is returned. Unnamed sponsors and partners of the project have pledged to fund this reward, described in the announcement as "friends and supporters" of BTCPay Server.
Anyone with information that could lead to the recovery of the stolen coins, including the attacker, is encouraged to come forward. If multiple individuals contribute to the return, the reward will be divided among them based on agreement with the affected parties, considering the scale of each individual's contribution, the share of recovered funds, and the practical significance of the information provided.
Additionally, the BTCPay Server Foundation will allocate 0.21 BTC each to Craig Raw, a developer of Sparrow Wallet, and to the Bitcoin Red Team volunteer group for their "responsible disclosure of the vulnerability." While the amounts are modest, the project explained that this is due to BTCPay's non-profit status as a Free and Open Source Software (FOSS) project.
We're donating 0.21 BTC to @craigraw and 0.21 BTC to the Bitcoin Red Team for their responsible security disclosure of the recent critical vulnerability.
In addition, friends and supporters of the BTCPay Server project have committed to funding a bounty to recover the stolen… pic.twitter.com/qhs8zwoCvM
— BTCPay Server (@BtcpayServer) August 10, 2026
The team has advised victims to report the incident to local law enforcement and to services where the stolen coins might have been sent. According to the developers, security services from exchanges, blockchain analytics firms, and authorities have offered assistance.
The full extent of the incident at BTCPay remains undisclosed, including the total losses and the number of affected nodes. A comprehensive analysis of the situation is expected to be released later.
BTCPay developers clarified that the attack specifically targeted connections with LND, and on-chain wallets were not affected. In version 2.4.2, public access to the LND API on Docker builds has been temporarily disabled — external wallets such as Zeus cannot connect through the BTCPay domain or onion address, but access will be restored after a security review.
The team is currently focused on patching vulnerabilities and enhancing code reviews with the help of external auditors, while also reviewing reports from Bitcoin Red Team, Project Loupe, Magic Grants, and independent researchers.
Users have been advised to store their funds in cold wallets. The shift in approach has been linked to the rise of AI: models are making the search for vulnerabilities faster and cheaper, which is turning many platforms into easy targets. Experts suggest that this reality may soon affect the entire software development industry.
“Artificial intelligence is shifting the balance of power: attackers gain the upper hand. Models are becoming smarter, making it cheaper and faster to find holes in large codebases. Bitcoin projects are the most tempting targets, but other software won't escape the same fate,” the BTCPay post stated.
It is worth noting that in August, following the Coldcard hack, Ledger's CTO Charles Guillemet emphasized the need to reassess the validation of random number generators in Bitcoin storage devices.
