Up to 3 $BTC is posted as a recovery bounty after BTCPay Server, an open-source Bitcoin payment processor, disclosed a critical exploit. BTCPay said AI may have been used to exploit the vulnerability, and credited Craig Raw and the Bitcoin Red Team fund with reporting the issue. The funds come from supporters, not a named corporate treasury.
Who surfaced the issue
Craig Raw and the Bitcoin Red Team fund are the credited reporters. BTCPay named both in its disclosure. That external parties identified the vulnerability is the key structural fact here: the path ran from outside researchers to BTCPay, then to the public record. Crediting external reporters in a security disclosure is standard practice. What it signals is that the vulnerability was not caught internally before the incident unfolded. Craig Raw is named without further characterization in the source. The Bitcoin Red Team fund is credited alongside him.
AI as a possible attack vector
BTCPay said AI "may have been used" to exploit the vulnerability. That phrasing is hedged, not confirmed. The disclosure did not provide specifics on the vulnerability type or the mechanism of exploitation. Naming AI as a possible tool in a public incident report is a meaningful act regardless of confirmation status. It tells operators running self-hosted BTCPay installations that automated or AI-assisted exploitation is now in the threat model for this software. The difference between "may have been used" and "was used" is material: one is a hypothesis worth naming publicly, the other is a forensic finding. The source provides no further detail on attribution or attacker identity.
The bounty
Three $BTC is the ceiling. The funds come from BTCPay supporters rather than a named institutional backer. The source does not specify what the bounty targets: recovered funds, attacker identification, details about the exploit chain, or something else. The ceiling and community-sourced structure suggest a voluntary coordination mechanism, not a formal payout governed by escrow. BTCPay's community put 3 BTC on the table. Whether that is sufficient depends on what the exploit actually cost, and the source does not say.