Attacker Identity and Incident Details
Published 8/11/2026, 12:12:23 PM
The identity of the attacker who drained BTCPay Server nodes remains unknown as of August 11, 2026. While the vulnerability was identified through responsible disclosure by security researchers, the exploit was actively used by anonymous actors to target high-profile Bitcoin entities. The $190,000 (3 BTC) bounty is widely viewed by the community as potentially inadequate to incentivize the return of funds, particularly if the total stolen amount significantly exceeds the bounty's 10% recovery cap.
Attacker Identity and Incident Details
The exploit, disclosed on August 7, 2026, involved a critical flaw in the Greenfield API that allowed unauthenticated remote access to sensitive LND macaroon credential files [Source: https://btcpayserver.org/security-alert-august-2026/]. This gave attackers full control over merchant Lightning nodes.
While the vulnerability was discovered and reported by Craig Raw (Sparrow Wallet) and the Bitcoin Red Team, the actual theft was carried out by unidentified parties [Source: https://www.coindesk.com/tech/2026/08/11/btcpay-server-lightning-exploit-details/].
| Victim | Impact Reported |
|---|---|
| Foundation | Passport-linked payment node drained overnight [Source: https://thecryptonomist.ch/2026/08/08/btcpay-server-exploit-victims-list/]. |
| Citadel21 | Lightning node swept and channels force-closed [Source: https://thecryptonomist.ch/2026/08/08/btcpay-server-exploit-victims-list/]. |
| Anonymous Operators | At least two additional operators confirmed losses [Source: https://thecryptonomist.ch/2026/08/08/btcpay-server-exploit-victims-list/]. |
Evaluation of the $190,000 Bounty
BTCPay Server issued a recovery bounty structured as 10% of recovered funds, capped at 3 BTC (approximately $190,000 at current market rates) [Source: https://cryptobriefing.com/btcpay-server-bounty-recovery-august-2026/].
The adequacy of this bounty is contested based on the following factors:
- Economic Incentive: The "no-questions-asked" reward is only attractive if the attacker has stolen less than ~$1.9 million. If the total haul is significantly higher, the 3 BTC cap provides little reason for a sophisticated actor to cooperate [Source: https://cryptobriefing.com/btcpay-server-bounty-recovery-august-2026/].
- Researcher Compensation: The primary researchers (Craig Raw and the Bitcoin Red Team) were awarded a separate "thank you" of 0.42 BTC, which is distinct from the recovery bounty intended for the attacker or informants [Source: https://cryptobriefing.com/btcpay-server-bounty-recovery-august-2026/].
- External Pressure: The bounty may only be effective if combined with the threat of identification. Blockchain analytics firms have already offered assistance to track the stolen funds, which may increase the "cost" of the attacker holding the assets [Source: https://btcpayserver.org/security-alert-august-2026/].
Conclusion: The attacker remains anonymous, and the $190,000 bounty is considered a modest incentive by modern industry standards, likely insufficient to guarantee the return of funds unless the attacker faces imminent risk of exposure.