BTCPay Server said supporters of the open-source bitcoin payment processor have committed a bounty of up to 3 BTC for the recovery of funds stolen through a recently disclosed vulnerability.

In a statement, the project said the bounty will pay 10% of whatever is recovered, with a ceiling of 3 BTC in the case of a full recovery. The offer was also extended directly to the attacker, as well as to anyone else with actionable information. BTCPay Server directed contacts to a dedicated security address and said Signal or other encrypted channels are available on request.
Exploit exposed Lightning admin credentials
BTCPay Server said hackers last week extracted Lightning Network admin macaroon credentials from affected server instances. The project published technical details and remediation guidance in a separate security advisory.
Addressing users who lost funds, the project said: 「We are sorry. We will examine our mistakes, but regret alone will not help affected users or secure the project. There is no time to waste. We have to learn, improve, and act quickly.」
Foundation to make disclosure donations
The BTCPay Server Foundation said it will donate 0.21 BTC to Sparrow Wallet developer Craig Raw and another 0.21 BTC to the Bitcoin Red Team fund in recognition of their responsible disclosure of the vulnerability.
Exchanges, analytics firms and law enforcement offered help
Separately, the project said security teams at exchanges, blockchain analytics firms, and law enforcement agencies have contacted it to offer assistance in tracking the stolen coins.
BTCPay Server is also asking affected users who have not yet come forward to share on-chain addresses and transaction details, and to file reports with local authorities and with any exchange or service where the funds appear. Individual reports, the project said, help preserve records and establish a chain of evidence that can improve the chances of freezing the funds.
Project says AI is changing the attack-defend balance
BTCPay Server added that improving AI models are making it faster and cheaper to scan large codebases for weaknesses, shifting the balance toward attackers. It said bitcoin projects are feeling that pressure first because they are unusually valuable targets.
The report first appeared in Bitcoin Magazine and was written by Mathew Di Salvo.

