Industry News

BTCPay Server Hit by Critical Exploit; Bounty Offered for Recovery

The Block · 11 Aug 2026
Key Takeaway If your business uses open-source or self-hosted payment software, monitor official security advisories closely and apply patches as soon as they're released.

BTCPay Server, an open-source payment processor used to accept cryptocurrency, has disclosed a critical vulnerability that was actively exploited. The organisation noted that artificial intelligence may have been used to help identify or exploit the flaw, highlighting a growing concern among security researchers that AI tools can lower the barrier for attackers to find and weaponise software weaknesses.

In response, supporters of the project have offered a bounty of up to 3 BTC to assist with recovery efforts following the exploit. BTCPay credited security researcher Craig Raw and the Bitcoin Red Team fund for reporting the issue, underscoring the important role independent researchers play in identifying and disclosing vulnerabilities before they cause wider harm.

While BTCPay Server is a specialised tool primarily used by businesses accepting cryptocurrency payments, the incident is a reminder that any software handling financial transactions is a high-value target for attackers. Businesses using open-source or self-hosted payment tools should stay alert to security advisories and apply patches promptly, as delays in updating systems can leave critical financial infrastructure exposed.

Summarised by CISO AI from The Block. We link back to every original so you can read it yourself.