DEALSSPG acquires DFW Crating & Packaging, entering the Dallas-Fort Worth marketSep 10, 2026
DEALSAGX declares $0.70 quarterly cash dividend, ex-date October 22Sep 10, 2026
EARNINGSCognyte Software narrows full-year guidance to $448 million on software mix shift and profitability accelerationSep 10, 2026
DEALSKTHAF declares THB 0.48 per-share cash dividend, ex-date and record date 23 September 2026Sep 10, 2026
DEALSTreasury's $6bn buyback fails to halt 30-year yield at 5.2%Sep 10, 2026
WORLDChina regulators warn banks against flooding IPO market with low-quality listingsSep 10, 2026
EARNINGSJ.J. McCarthy demoted to third string as Vikings name Wentz backup ahead of Green Bay openerSep 10, 2026
KALAKALA BIO sets November 3 annual meeting; stockholder nomination window closes September 19Sep 9, 2026
DEALSSPG acquires DFW Crating & Packaging, entering the Dallas-Fort Worth marketSep 10, 2026
DEALSAGX declares $0.70 quarterly cash dividend, ex-date October 22Sep 10, 2026
EARNINGSCognyte Software narrows full-year guidance to $448 million on software mix shift and profitability accelerationSep 10, 2026
DEALSKTHAF declares THB 0.48 per-share cash dividend, ex-date and record date 23 September 2026Sep 10, 2026
DEALSTreasury's $6bn buyback fails to halt 30-year yield at 5.2%Sep 10, 2026
WORLDChina regulators warn banks against flooding IPO market with low-quality listingsSep 10, 2026
EARNINGSJ.J. McCarthy demoted to third string as Vikings name Wentz backup ahead of Green Bay openerSep 10, 2026
KALAKALA BIO sets November 3 annual meeting; stockholder nomination window closes September 19Sep 9, 2026

BTCPay Server backers offer up to 3 BTC recovery bounty following critical exploit

Up to 3 $BTC is posted as a recovery bounty after BTCPay Server, an open-source Bitcoin payment processor, disclosed a critical exploit. BTCPay said AI may have been used to exploit the vulnerability, and credited Craig Raw and the Bitcoin…

By Warren Ashby·Aug 11, 2026·2 min read·crypto·$BTC

Key takeaways

  • BTCPay Server, an open-source Bitcoin payment processor, disclosed a critical exploit and its backers posted a recovery bounty of up to 3 BTC.
  • The bounty funds come from BTCPay supporters rather than a named corporate or institutional treasury.
  • BTCPay said AI "may have been used" to exploit the vulnerability, a hedged claim it did not confirm.
  • BTCPay credited Craig Raw and the Bitcoin Red Team fund with reporting the vulnerability.
  • The disclosure did not specify the vulnerability type, the exploitation mechanism, or what the bounty specifically targets.

Up to 3 $BTC is posted as a recovery bounty after BTCPay Server, an open-source Bitcoin payment processor, disclosed a critical exploit. BTCPay said AI may have been used to exploit the vulnerability, and credited Craig Raw and the Bitcoin Red Team fund with reporting the issue. The funds come from supporters, not a named corporate treasury.

Who surfaced the issue

Craig Raw and the Bitcoin Red Team fund are the credited reporters. BTCPay named both in its disclosure. That external parties identified the vulnerability is the key structural fact here: the path ran from outside researchers to BTCPay, then to the public record. Crediting external reporters in a security disclosure is standard practice. What it signals is that the vulnerability was not caught internally before the incident unfolded. Craig Raw is named without further characterization in the source. The Bitcoin Red Team fund is credited alongside him.

AI as a possible attack vector

BTCPay said AI "may have been used" to exploit the vulnerability. That phrasing is hedged, not confirmed. The disclosure did not provide specifics on the vulnerability type or the mechanism of exploitation. Naming AI as a possible tool in a public incident report is a meaningful act regardless of confirmation status. It tells operators running self-hosted BTCPay installations that automated or AI-assisted exploitation is now in the threat model for this software. The difference between "may have been used" and "was used" is material: one is a hypothesis worth naming publicly, the other is a forensic finding. The source provides no further detail on attribution or attacker identity.

The bounty

Three $BTC is the ceiling. The funds come from BTCPay supporters rather than a named institutional backer. The source does not specify what the bounty targets: recovered funds, attacker identification, details about the exploit chain, or something else. The ceiling and community-sourced structure suggest a voluntary coordination mechanism, not a formal payout governed by escrow. BTCPay's community put 3 BTC on the table. Whether that is sufficient depends on what the exploit actually cost, and the source does not say.

Share
Source: theblock.co
© 2026 NewsMeter

Frequently asked

How large is the recovery bounty and where does the money come from?

The bounty is up to 3 BTC, and the funds come from BTCPay supporters rather than a named institutional backer.

Who reported the vulnerability to BTCPay Server?

BTCPay credited Craig Raw and the Bitcoin Red Team fund as the reporters, meaning external researchers surfaced the issue rather than it being caught internally.

Was AI confirmed to be used in the exploit?

No; BTCPay only said AI "may have been used," which is a hedged hypothesis rather than a confirmed forensic finding.

What exactly does the bounty target?

The source does not specify whether the bounty is for recovered funds, attacker identification, exploit-chain details, or something else.

Did BTCPay disclose how the exploit worked?

No; the disclosure provided no specifics on the vulnerability type, the mechanism of exploitation, or the attacker's identity.