EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Blockstream takes tough line against Liquid Network hacker who extorted 598 bitcoins

2026-09-11 20:43:00
Bookmark

Key Points

  • Blockstream refused to satisfy the blackmailers, who withheld approximately 598.5 BTC after the Liquid Network was breached.
  • On September 6, 2026, the attacker initially extracted nearly 4,000 BTC from Liquid's alliance wallet.
  • After the security patch was deployed in Blockstream, approximately 3,400 BTC was returned, with approximately 15% still outstanding.
  • The attacker issued an ultimatum to pay a 10% reward from the Blockstream vault, or threatened Liquid users to face a 15% loss.
  • The company announced plans to work with authorities, cryptocurrency exchanges and blockchain forensics experts to track stolen assets.

The company's firm response

Blockstream firmly rejected extortion demands from attackers who currently hold approximately 598.5 BTC after the Liquid Network security breach. The company characterized the incident as criminal theft and announced that it would recover the stolen assets through official investigative channels.

To those who steal Liquid Network bitcoins:

Blockstream will not pay ransoms to return stolen funds. Obtaining assets without authorization and withholding them for return is a criminal act, not a responsible disclosure. This is not white hat behavior. This is...

-- Blockstream (@Blockstream) September 11, 2026

The security breach occurred on September 6, 2026, when a group of individuals calling themselves "white hats" extracted nearly 4,000 BTC from Liquid's alliance wallet. Based on market prices at the time, the value of the withdrawn amount was approximately US$320 million.

Liquid is a Bitcoin sidechain developed and operated by Blockstream. After an unauthorized withdrawal, the network operator temporarily stopped block generation while the technical team was investigating and resolving the vulnerability.

Blockstream's technical analysis traces the root cause to cache key conflicts in the confidential transaction verification mechanism. The investigation determined that the alliance encryption key remained secure and uncompromised throughout the incident.

After Blockstream deployed a security patch to the affected bridging infrastructure, the attacker returned 3,400 BTC to Alliance Wallet on September 7. This repayment accounted for approximately 85% of the original withdrawal.

The remaining 598.5 BTC remains in addresses controlled by the attacker. At the time of partial refunds, the market value of these remaining coins was close to $47 million.

The attacker then modified its conditions. Using a blockchain-based messaging system, they asked Blockstream to pay a 10% reward from the company's reserves. They threatened to permanently bear a 15% loss if they refused.

Future recovery strategies

According to Blockstream's statement, attackers can choose to voluntarily return bitcoins that comply with the established White Hat Security Research Protocol. If they fail to do so, the company intends to launch a comprehensive recycling effort involving law enforcement agencies, cryptocurrency exchanges, financial service providers and blockchain forensics experts.

The transparent nature of Bitcoin's distributed ledger allows continuous monitoring of the flow of funds originating from addresses associated with the vulnerability, regardless of how subsequent wallets are subdivided or transferred.

Blockstream cited the Coldhead security incident as a precedent, where Galaxy Research records showed that 1,561 BTC remained stationary after addresses controlled by attackers were distributed to exchanges and compliance departments.

Liquid Network resumed block generation on Thursday after implementing an emergency software patch, but transaction processing and Bitcoin bridging operations were still temporarily disabled at the time of release.

Blockstream conveyed its ongoing commitment to affected users and expressed its gratitude to the engineers, cryptography experts and security professionals who contributed to vulnerability identification and remediation.

"Blockchain transactions create a permanent record, and the forensic evidence they produce will exist indefinitely," the company emphasized.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP