Loading market data...

BTCPay Server Offers 3 BTC Bounty for Recovery of Stolen Funds

BTCPay Server Offers 3 BTC Bounty for Recovery of Stolen Funds

BTCPay Server is offering up to 3 Bitcoins to anyone who can help recover funds stolen in a wallet exploit last week. The bounty, set at 10% of recovered funds with a 3 BTC cap for full recovery, is open to the attacker and anyone with actionable information. The project also published technical details and remediation guidance in a separate security advisory.

The bounty terms

The offer is straightforward: if you help get the money back, you get a cut. The project set up a dedicated security address and encrypted channels for people to come forward. That includes the attacker, who could theoretically claim the reward without facing legal trouble — though law enforcement is already involved.

How the exploit worked

Hackers extracted Lightning Network admin macaroon credentials from affected BTCPay Server instances. Those credentials are essentially the keys to the kingdom, letting an attacker move funds or tamper with the node. The project's advisory walks through the vulnerability and how to patch it, but the damage was already done for some users.

Goodwill payments and outside help

In a separate move, the BTCPay Server Foundation donated 0.21 BTC to Sparrow Wallet developer Craig Raw and another 0.21 BTC to the Bitcoin Red Team fund. Both are being recognized for responsible disclosure — a reminder that not every vulnerability gets exploited. Meanwhile, exchanges, blockchain analytics firms, and law enforcement have offered to help track the stolen coins. The project is asking affected users to share on-chain addresses and transaction details, and to file reports with local authorities and exchanges.

Why this is getting harder

The timing isn't great. The project notes that improving AI models are making it faster and cheaper to find vulnerabilities, shifting the balance toward attackers. Bitcoin projects, with their high-value targets and often small security teams, are unusually exposed. That's not an excuse — it's a warning. The bounty is a practical step, but it also signals how serious the threat has become.

Affected users should act now: pull your on-chain data, file reports, and send the details to the security address. The clock is ticking on the bounty, and every hour gives the hackers more time to launder the funds.