“We will examine our mistakes, but regret alone will not help affected users or secure the project,” the company wrote. “There is no time to waste. We have to learn, improve, and act quickly.”
BTCPay has not disclosed how much Bitcoin was stolen, how many users were affected, or whether any funds have been recovered.
If multiple tips help recover the funds, the bounty will be divided in coordination with victims. The project said it would consider each victim’s losses, the amount recovered, and the usefulness of each tip.
“These are modest contributions, but they are what we can offer as a FOSS project and a way to appreciate people doing critical security work, which helps the entire ecosystem,” BTCPay wrote.
The company said it is strengthening code reviews and prioritizing security patches over new features as AI is making it easier for attackers to find vulnerabilities in Bitcoin software.
“Defending software in this environment requires better tools, more thorough reviews, faster security responses, and support for researchers who find and responsibly report vulnerabilities,” BTCPay wrote.


















