5x rewards · Early stage
Bitcoin

Blockstream Refuses Ransom Demand After $47 Million Liquid Hack

Ilustración: a dim server room with rows of humming hardware. Ilustración generada con IA.
Ilustración generada con IA

Blockstream has publicly rejected a ransom demand from the attackers who drained hundreds of millions of dollars from its Liquid Network sidechain, calling the incident theft rather than a good-faith security disclosure. The company said it will pursue law enforcement and forensic investigation if the roughly 598.5 BTC still missing, worth close to $47 million, is not returned in full.

The statement, issued Friday, September 11, 2026, marks a hardening of tone from Blockstream after nearly a week of confusion over how to characterize the breach. It also sets up a tense standoff between a major Bitcoin infrastructure operator and attackers who framed their actions as an aggressive bug bounty negotiation rather than a straightforward crime.

How the Exploit Unfolded

The attack began on a Sunday and exploited a flaw in how Liquid nodes cached range proof verifications, a mechanism meant to confirm that transactions on the sidechain are properly backed. By manipulating this caching process, attackers were able to mint unbacked L-BTC, the Liquid-pegged version of bitcoin, and swap it for real reserve bitcoin through SideSwap, a federation member with authorization to process peg-outs. Blockstream had already halted operations after the initial $320 million withdrawal was detected, as roughly 4,000 BTC was drained and the network’s reserve collapsed to just 197 BTC.

The response that followed moved quickly by blockchain-security standards. Bridge nodes were patched within 10 hours of the exploit, attackers returned about 3,400 BTC the following Monday, and Blockstream shipped a formal fix, Elements v23.3.4, on Wednesday. Block production and transactions on Liquid resumed Thursday, though peg-outs — the process of converting L-BTC back into mainchain bitcoin — remain disabled as a precaution while the network is monitored.

What the Ransom Demand Reveals

What distinguishes this case from a routine exploit is the negotiation that followed. The attackers reportedly demanded 10% of the stolen funds, framing it as a bug bounty payment, and threatened that holders would face a 15% loss if the demand went unmet. They also argued that Blockstream had underinvested in security, claiming the company allocated as little as $1.5 million — or possibly nothing at all — in bug bounty funding to protect a sidechain securing an estimated $5 billion in assets.

Blockstream’s public rebuttal rejects that framing outright. By insisting the episode is theft rather than responsible disclosure, the company is drawing a clear line against a pattern seen elsewhere in the industry, where attackers exploit protocols and then attempt to extract a “reward” for partial restitution under threat of keeping the rest. That dynamic differs sharply from other recent incidents in crypto security, such as the case in which Cronos rewrote its blockchain history to undo an exploit rather than negotiate with an attacker directly. Blockstream’s approach instead leans on the threat of forensic tracing and law enforcement engagement, a strategy that keeps open the possibility of recovering funds without legitimizing the extortion attempt.

Notably, an earlier incident report from Liquid had described the situation as one involving a “white hat hacker,” language Blockstream has since disputed. That reversal matters: white-hat framing typically implies a security researcher acting in good faith to expose a vulnerability, often in exchange for an agreed bounty. Blockstream’s decision to abandon that characterization signals it now views the entire episode, including the partial fund return, as a pressure tactic rather than cooperation.

What to Watch Next

Several threads remain open. The most immediate is whether the outstanding 598.5 BTC is returned voluntarily or becomes the subject of a prolonged law enforcement effort, which would test how traceable bitcoin moved through a sidechain and swap infrastructure like SideSwap actually is. Peg-outs on Liquid remain suspended, and their reinstatement will likely serve as a signal of how confident Blockstream is in the durability of its patch.

Security researchers and node operators should also be alert to a secondary risk Blockstream flagged: scammers impersonating official update sites to target operators seeking to install the patched software, a reminder that high-profile exploits often generate opportunistic follow-on fraud. More broadly, the episode is likely to renew scrutiny of bug bounty funding across Bitcoin-adjacent infrastructure projects, particularly as sidechains and bridges continue to secure billions of dollars in value while often running on comparatively modest security budgets. How Blockstream’s standoff resolves may become a reference point for how other infrastructure providers respond when confronted with similar extortion attempts following a breach.

Source: Decrypt

This content is for informational purposes only and does not constitute financial or investment advice.

Informational and educational content; not financial, investment, legal or tax advice. Always do your own research.

Read. Comment. Earn.

Share a thoughtful take on this story. Quality comments are scored by AI and earn reward points.

Points (Proof Points) are internal and non-transferable, with no monetary value and no entitlement to $PROOF. Legal

Join the conversation