Crypto & Web3

BTCPay Server posts 3 BTC bounty after wallet theft

BTCPay Server posts 3 BTC bounty after wallet theft

BTCPay Server documentation

Supporters of the self-hosted payment processor BTCPay Server have put money behind an attempt to claw back coins taken in a recently disclosed wallet exploit. The bounty pays 10 percent of whatever is recovered and is capped at three Bitcoins if everything comes back, according to Bitcoin Magazine’s report on the BTCPay Server statement.

The offer is unusually blunt about who may claim it. The project extended the same terms to the attacker as to any third party sitting on useful information, pointing both toward a dedicated security address and offering Signal or another encrypted channel on request, Bitcoin Magazine reported.

What was actually stolen

The theft did not break Bitcoin or the Lightning Network itself. Attackers pulled Lightning admin macaroon credentials out of affected BTCPay Server instances last week, and the project published technical details and remediation steps in a separate security advisory on its documentation site. An admin macaroon is effectively a full-permission key to a node, so anyone holding one can move funds without touching the software’s login flow, per Bitcoin Magazine’s account of the incident.

That distinction matters for operators. If you run BTCPay Server yourself, the practical exposure is your own node’s credential material, not a protocol flaw you have to wait for someone else to fix.

Where the money is going

Two payments are already committed. The BTCPay Server Foundation said it will send 0.21 Bitcoins to Sparrow Wallet developer Craig Raw and another 0.21 Bitcoins to the Bitcoin Red Team fund for responsibly disclosing the vulnerability, Bitcoin Magazine reported. Paying disclosure rather than only chasing recovery is the part other small open-source projects should copy. Craig Raw’s Sparrow Wallet is a desktop Bitcoin wallet focused on privacy and coin control.

The project also said it has heard from exchange security teams, blockchain analytics firms and law enforcement offering help tracing the coins, and it is asking affected users who have stayed quiet to hand over on-chain addresses and transaction details and to file reports locally and with any service where funds surface. Individual reports, the project argued, build a chain of evidence that improves the odds of a freeze.

The uncomfortable part

Alongside the apology — “we will examine our mistakes, but regret alone will not help affected users or secure the project” — the team said it will prioritise security patches over new features indefinitely, and argued that improving AI models make it cheaper to sweep large codebases for weaknesses, which puts Bitcoin projects first in line because they hold unusually valuable targets.

The project’s decision to route 0.21 BTC each to Sparrow Wallet developer Craig Raw and the Bitcoin Red Team fund reflects a disclosure-first posture that differs from the typical “pay only for recovered coins” model. The Bitcoin Red Team fund supports open-source security research across the ecosystem.

Readers tracking the wider fallout from recent Bitcoin custody incidents can compare this with inflows into Bitcoin ETFs after the Coldcard episode, and with how paid bug bounty programmes handle disclosure risk in our look at bounty techniques and legal exposure.

If you operate a node, the immediate action is narrow: apply the advisory’s remediation, rotate macaroons, and assume any credential that left the machine is burned. The broader signal is that self-hosted Bitcoin infrastructure is now carrying exposure that its maintainers are willing to put real money behind cleaning up — and that the same AI tooling making codebases easier to audit is also making them easier to sweep for weaknesses.

Editorially independent: we accept no payment for coverage and currently use no affiliate links. Read our Editorial Standards and Corrections Policy. Published: Aug 14, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.