EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Blockstream refused to pay Liquid ransom, calling it theft

2026-09-12 04:20:25
Bookmark

Blockstream refused to pay ransom, calling the hacking theft

About 598 bitcoins were still held after the Liquid Network was attacked. Blockstream refused to pay the ransom and made it clear that it was not a white hat safety test, but a theft.

On September 11, Blockstream told those who had drained funds from its Liquid Network sidechains that the approximately 598.5 bitcoins (worth approximately US$47 million) remaining in their hands were stolen property rather than a loophole bounty. The company unequivocally rejected the "white hat" label: "This is not white hat activity, this is theft."

Negotiations end and recovery begin

This statement ended a week-long on-chain game and launched a forensic tracking operation. Previously, the attacker asked Blockstream to pay a 10% reward from its own funds and threatened to face a 15% loss if it refused. However, when most of the funds had been repatriated, the company was able to redefine the remaining balance as extortion rather than a negotiated payment.

Blockstream's argument goes beyond the amount itself: Open source developers maintaining shared Bitcoin infrastructure should not be forced to hand over huge amounts of money far beyond their own interests when any code is exploited; at the same time, users should not suffer losses to fund the attacker's exit.

The timeline from the withdrawal of funds to the formal rejection

The entire negotiation process is carried out entirely on-chain, passed through a signed message between a listed company and a wallet that has just emptied its reserves:

  • September 6: The attacker extracted nearly 4000 bitcoins (about 95% of the reserve) and issued a statement claiming "white hat" intent.
  • September 7 : Bridge nodes are patched. The attackers returned approximately 3400 bitcoins (approximately 85%) and retained 598.5 bitcoins.
  • September 9 : Samson Mow made a 10% reward request with a 15% loss threat against the holder.
  • September 10 : Liquid Network resumed block production at 19:55 UTC. Trading resumed, but redemption remained disabled.
  • September 11 : Blockstream issued a rejection statement and said it would turn to law enforcement agencies and forensic experts for help.

Why the vault was emptied without losing the key

No phishing attack occurred, and no hardware modules were cracked. Liquid escrow wallets are located behind an 11-of-15 multi-signature mechanism, which means that at least eleven of the fifteen vetted members need to sign off to make any withdrawals. These signatures are generated because the transaction appears to be routine. The problem lies at the software level.

A proof-of-scope cache vulnerability exists in Elements (the open source code that drives the Liquid Network) that allows attackers to mint L-BTC without any backup assets. The scope certificate is a verification mechanism that confirms that confidential transactions are actually endorsed without disclosing the amount. When the verification mechanism reuses an approved cached result, the network releases some short tokens. Subsequently, these counterfeit L-BTC left the system through the normal SideSwap redemption channel. SideSwap said its own authorization key was never violated.

  1. Cache vulnerability skips full proof of scope verification.
  2. The attacker forged L-BTC without endorsements.
  3. Tokens are redeemed through the SideSwap redemption channel.
  4. Multiple signatures confirm that the real Bitcoin has left the vault.

The loss is reflected in the endorsement ratio. Blockstream has released Elements v23.3.4 to fix the bug, and transactions are resuming, but L-BTC's mortgage ratio is currently only about 85%, and redemption is still off. Until this gap is filled, tokens that are substitutes for Bitcoin cannot be fully redeemed.

Funding status

Project Value Pre-attack reserves About 4,200 BTC Amount withdrawn About 4, 000 BTC /approximately US$320 million Amount returned to the alliance approximately 3, 400 BTC (85%) Amount still held by the attacker 598.5 BTC /approximately US$47 million Current L-BTC mortgage rate approximately 85%

The restart announcement suggests that the network is still watching cautiously.

Liquid's status update released on September 10 described the recovery as a stage rather than an end. Block production has resumed and functional nodes have signed transactions again, but there is no date when the redemption function will be reopened due to ongoing testing, AI-assisted code scanning and real-time monitoring by internal and external teams. Node operators are required to immediately upgrade to Elements v23.3.4, while ordinary users are advised to stay put.

The announcement also included a warning, which was also a sign: reports of false updates to websites and information leading people to fake channels. This is a reminder that just as patches are released, speculators can quickly hunt damaged networks.

Red team allegations and Blockstream's denials

A public debate over who knew in advance complicates the otherwise clear story of the coded accident. The Bitcoin Red Team, a volunteer organization that audits bitcoin-related projects, said it disclosed the flaw before it was exploited.

Co-founder Calle claimed that Blockstream ignored the organization's emails and sarcastically said that ignoring the red team emails ultimately cost the company hundreds of coins. CEO Adam Back attributed the vulnerability to erroneous fixes to non-critical issues discovered by AI, while Samson Mow insisted no emails were ignored. Calle countered that Blockstream selectively cited its patch and said the organization would publish its own version in an after-the-fact report.

The controversy is critical because a fix was reportedly written and merged, but at the time of the attack, no released build contained the fix.

Lessons should be learned by every bridging operator

This incident is a warning to all those operating co-hosting or cross-chain bridging. This attack shows that cache shortcuts in automatic verification can quietly override all manual safeguards superimposed on them, and that such vulnerability types can be transferred directly to other designs.

A new third-party review of deposit and withdrawal logic is expected, and exchanges will also explain settlement level risks to institutional clients in more straightforward terms. Currently, the recovery of the remaining 598.5 BTC will be conducted through law enforcement agencies, exchanges and forensic experts rather than through the negotiation table, although Blockstream leaves open the possibility for voluntary return.

Two documents that have not been officially released will determine how this matter will be remembered: the company's post-mortem analysis report and the disclosure that the red team has promised to disclose.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP