pull down to refresh

tl;dr - BTCPay Server Foundation awards 0.21 BTC to Craig Raw and 0.21 BTC to Red Team for responsible disclosure. And up to .3 BTC for information leafing to recovery of funds.


We will share more details and acknowledge the organizations supporting this work once the arrangements are finalized.

Prioritizing security releases

For the foreseeable future, we are prioritizing security patches and hardening over major new features.

As a security practice, keep funds in cold storage whenever possible. If you need a hot wallet for daily operations, regularly move excess funds to cold storage, especially during this period of rapid, AI-driven change.

The environment has changedThe environment has changed

AI is changing the balance between attackers and defenders. As models improve, it becomes faster and cheaper to inspect large codebases and find weaknesses.

Bitcoin projects are particularly exposed because they are valuable targets. The rest of the software industry will face the same reality.

Defending software in this environment requires better tools, more thorough reviews, faster security responses, and support for researchers who find and responsibly report vulnerabilities.

If we give up open source or self-custody because defending them is difficult, we give up the freedom Bitcoin was created to protect.

To the users who lost funds: we are sorry.

We will examine our mistakes, but regret alone will not help affected users or secure the project. There is no time to waste. We have to learn, improve, and act quickly.

Thank you to everyone in the community, who reported issues, helped affected users, shared information, contacted exchanges, and supported the project through this incident.

0 sats \ 0 replies \ @88e5b8ee25 12h freebie -30 sats

Security incidents are the real test of an open-source project - not the code, but the response. Post-mortem transparency like this is what keeps self-hosters trusting the project with their channels. Curious whether the incident was an exposed dependency or a deployment-specific issue.

2 sats \ 0 replies \ @fifoofa 3h -30 sats

Gotta hand it to them, this is the right shape of a response - bounties public, timeline promised, cold storage reminder. The part worth auditing now is how hundreds of claimed findings still let the real one through. Paying researchers is good, fixing the pipeline that missed the actual exploit is better.