Attacker Identity and Incident Details

Published 8/11/2026, 12:12:23 PM

The identity of the attacker who drained BTCPay Server nodes remains unknown as of August 11, 2026. While the vulnerability was identified through responsible disclosure by security researchers, the exploit was actively used by anonymous actors to target high-profile Bitcoin entities. The $190,000 (3 BTC) bounty is widely viewed by the community as potentially inadequate to incentivize the return of funds, particularly if the total stolen amount significantly exceeds the bounty's 10% recovery cap.

Attacker Identity and Incident Details

The exploit, disclosed on August 7, 2026, involved a critical flaw in the Greenfield API that allowed unauthenticated remote access to sensitive LND macaroon credential files [Source: https://btcpayserver.org/security-alert-august-2026/]. This gave attackers full control over merchant Lightning nodes.

While the vulnerability was discovered and reported by Craig Raw (Sparrow Wallet) and the Bitcoin Red Team, the actual theft was carried out by unidentified parties [Source: https://www.coindesk.com/tech/2026/08/11/btcpay-server-lightning-exploit-details/].

VictimImpact Reported
FoundationPassport-linked payment node drained overnight [Source: https://thecryptonomist.ch/2026/08/08/btcpay-server-exploit-victims-list/].
Citadel21Lightning node swept and channels force-closed [Source: https://thecryptonomist.ch/2026/08/08/btcpay-server-exploit-victims-list/].
Anonymous OperatorsAt least two additional operators confirmed losses [Source: https://thecryptonomist.ch/2026/08/08/btcpay-server-exploit-victims-list/].

Evaluation of the $190,000 Bounty

BTCPay Server issued a recovery bounty structured as 10% of recovered funds, capped at 3 BTC (approximately $190,000 at current market rates) [Source: https://cryptobriefing.com/btcpay-server-bounty-recovery-august-2026/].

The adequacy of this bounty is contested based on the following factors:

Conclusion: The attacker remains anonymous, and the $190,000 bounty is considered a modest incentive by modern industry standards, likely insufficient to guarantee the return of funds unless the attacker faces imminent risk of exposure.