BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Blockstream Refuses Liquid Ransom, Calls It Theft

Blockstream refused to pay a ransom for the roughly 598 BTC still held after the Liquid Network exploit. The company called the holdout theft, not white-hat security work. The attackers wante

AnonymousCryptoCompass newsroom
September 11, 2026
6 min read
NEWS
Blockstream Refuses Liquid Ransom, Calls It Theft
CryptoCompass editorial visual for bitcoin coverage.
  • Blockstream refused to pay a ransom for the roughly 598 BTC still held after the Liquid Network exploit.
  • The company called the holdout theft, not white-hat security work.
  • The attackers wanted a 10% bounty from Blockstream’s own funds and threatened a 15% loss for holders.
  • The Bitcoin Red Team says it warned Blockstream about the bug, a claim the company disputes.

Blockstream will not pay to get the rest of its stolen Bitcoin back. On September 11 the company told the people who drained its Liquid Network sidechain that the roughly 598.5 BTC still in their hands, worth about $47 million, is stolen property rather than a bug bounty. It rejected their white-hat label without hedging: “It is not white-hat activity. It is theft.” The statement closes a week of on-chain bargaining and opens a forensic chase.

The demand: 10% from Blockstream, or a 15% hit to holders

The attackers were not asking to be reimbursed for finding a flaw. They wanted Blockstream to pay a 10% bounty out of its own corporate treasury, and warned that Liquid holders would eat a 15% loss if it refused. That threat arrived after most of the money had already come back, which is what let the company reframe the balance as ransom instead of a negotiated payout. Blockstream’s argument reached past the dollar figure: open-source developers who maintain shared Bitcoin infrastructure should not be forced to hand over a sum that dwarfs their own stake every time someone exploits their code, and users should not be haircut to fund an attacker’s exit.

Six days from drain to refusal

The negotiation played out entirely on-chain, in signed messages passed between a public company and the wallet that had just emptied its reserves.

Sep 6

Attackers pull close to 4,000 BTC, about 95% of the reserve, and post a note claiming white-hat intent.

Sep 7

Bridge nodes are patched. The actors return about 3,400 BTC, roughly 85%, and keep 598.5 BTC.

Sep 9

Samson Mow surfaces the 10% demand and the 15% haircut threat attached to it.

Sep 10

Liquid restarts block production at 19:55 UTC. Transactions resume, peg-outs stay disabled.

Sep 11

Blockstream publishes its refusal and signals a move to law enforcement and forensics.

Why the vault emptied without a stolen key

No key was phished and no hardware module was cracked. The Liquid peg wallet sits behind an 11-of-15 multisig, so at least eleven of fifteen vetted members must sign any withdrawal, and those signatures were produced because the transaction looked ordinary. The break lived in the software. A range-proof cache bug in Elements, the open-source code that powers Liquid, let the attackers mint L-BTC with nothing behind it. A range proof is the check that confirms a confidential transaction is actually backed without revealing the amount, and when that check reused an already-approved cached result, the network waved through empty tokens. The fake L-BTC then left through a normal door, a SideSwap peg-out, the process that redeems L-BTC for real Bitcoin. SideSwap says its own authorization key was never compromised.

1

Cache bug skips full range-proof validation.

2

Attackers mint unbacked L-BTC.

3

Tokens redeemed through a SideSwap peg-out.

4

The multisig signs, and real BTC leaves the vault.

The damage shows up in the backing. Blockstream shipped Elements v23.3.4 to close the hole and transactions are moving again, but L-BTC is only about 85% collateralised while peg-outs remain switched off. Until that gap closes, the token exchanges treat as a Bitcoin stand-in is not fully redeemable.

Where the money stands Figure Reserve before the drain~4,200 BTCAmount drained~4,000 BTC / ~$320MReturned to the federation~3,400 BTC (85%)Still held by attackers598.5 BTC / ~$47MCurrent L-BTC backing~85% 

The restart notice reads like a network still holding its breath

Liquid’s own status update from September 10, frames the resumption as one stage rather than a finish line. Block production is back and functionary nodes are signing again, yet peg-outs stay locked while internal and external teams run testing, AI-assisted code scanning and live monitoring, with no date given for when redemptions reopen. Node operators are told to move to Elements v23.3.4 without delay, while ordinary users are asked to sit tight. The notice also carries a warning that doubles as its own signal: reports of fake update sites and messages steering people toward bogus channels, a reminder that opportunists circle a wounded network as quickly as the patch ships.

The Red Team says it emailed a warning. Blockstream says no.

A public fight over who knew what has complicated the cleaner story of a coding accident. The Bitcoin Red Team, a volunteer group that audits Bitcoin-aligned projects, indicated it had already disclosed the flaw before it was used. Co-lead Calle said Blockstream ignored the group’s emails, and jabbed that ignoring a Red Team message had ended up costing the company hundreds of coins.

CEO Adam Back attributed the bug to an incorrect fix applied to an AI-found, non-critical issue, and Samson Mow insisted no emails were ignored. Calle countered that Blockstream referenced its patches selectively and said the group will publish its own account once a postmortem lands. The dispute matters because a fix had reportedly been written and merged, yet no released build carried it when the exploit hit.

What every bridge operator takes from this

The lesson lands on anyone running a federated peg or a cross-chain bridge. This exploit showed that a caching shortcut in automated validation can quietly override every human safeguard stacked on top of it, and the bug class transfers directly to other designs. Expect fresh third-party reviews aimed squarely at peg-in and peg-out logic, and expect exchanges to spell out settlement-layer risk to institutional clients in plainer terms. Recovery of the outstanding 598.5

BTC now runs through law enforcement, exchanges and forensic specialists rather than the negotiating table, though Blockstream left the door open for a voluntary return. Two unwritten documents will decide how this is remembered: the company’s postmortem and the Red Team’s promised account of the disclosure.

The post Blockstream Refuses Liquid Ransom, Calls It Theft appeared first on ETHNews.