Crypto

Blockstream Rejects $47 Million Bitcoin Bounty After Liquid Network Exploit

Blockstream refuses ransom demand as 598.5 BTC remains with attackers

SAN FRANCISCO — Blockstream has rejected a 10% payment demanded by the exploiters of its Liquid Network, refusing to send a multi-million dollar “bug bounty” from corporate funds. The blockchain infrastructure firm said taking assets without authorization and withholding their return is “a crime, not responsible disclosure,” adding: “It is not white-hat activity. It is theft.”

The breach on Sunday drained approximately 4,000 Bitcoin (BTC), valued at roughly $320 million, from the federated sidechain. The unidentified attackers returned 3,400 BTC on Monday, but 598.5 BTC—approximately $47 million—remains in a single digital wallet. They have demanded a 10% payout to return the remainder.

Liquid’s operators initially said in an incident report published Tuesday that they were “coordinating with the white hat hacker” to restore the system. Talks later broke down after public on-chain messages exchanged Wednesday exposed the disagreement over the terms of the return. The attackers accused Blockstream of allocating “only $1.5M (maybe even 0) to secure $5B assets” and called the company’s security posture “a flagrant neglect of security.”

The exploit depended on a technical vulnerability in Elements, the open-source sidechain software that powers Liquid. Liquid nodes cached range proof verifications incorrectly; these cryptographic tools prove a transaction’s value without revealing its exact amount. The flaw allowed the attackers to artificially mint unbacked L-BTC, or wrapped “Liquid Bitcoin.”

Blockstream engineers deployed patches to the network’s bridge nodes within ten hours of the attack. The company released Elements version 23.3.4 by Wednesday as a mandatory security update for node operators, while also warning them about phishing attempts and fake update portals circulating online.

Liquid was launched by Blockstream in 2018 as a federated sidechain to the main Bitcoin blockchain. Built for institutional traders and exchanges, it supports faster, more confidential transactions and the issuance of digital assets. Its distributed consensus system relies on “functionaries”—independent cryptocurrency firms and exchanges that collectively manage the network’s Bitcoin reserves through a multi-signature custody system.

Using the unbacked tokens, the exploiters began a “peg-out” process to withdraw actual Bitcoin from the reserve pool. They routed the transaction through SideSwap, a decentralized exchange and Liquid Federation member with active peg-out authorization keys. The drain reduced Liquid’s collateral reserves to just 197 BTC before developers detected the anomaly.

Liquid resumed block production and standard transaction processing on Thursday. Its peg-out functionality remains temporarily offline as a security precaution while the team completes final recovery operations. The remaining 598.5 BTC has stayed stationary in the attacker’s wallet since the initial exploit.

The attackers threatened to permanently withhold the funds unless Blockstream paid the bounty directly from its capital. “You will cause all your holders a 15% loss for your irresponsibility and stinginess,” they wrote. Blockstream said its involvement in the initial discussions was intended to recover the assets and did not represent acceptance of the hackers’ terms or actions.

The dispute has intensified debate over the limits of “white-hat” hacking in the digital asset industry. In several earlier high-profile decentralized finance (DeFi) exploits, protocols agreed to lucrative bounty payments—sometimes worth tens of millions of dollars—in exchange for the safe return of user funds. Blockstream is rejecting that precedent, arguing that yield-bearing compromises should not expose open-source developers to ransom demands far exceeding their financial stake in the software.

By refusing the demand, Blockstream is seeking a firmer boundary for open-source development groups increasingly targeted by sophisticated exploiters seeking legal immunity under the guise of “security auditing.” The company also ruled out a “haircut,” a mechanism that would distribute the financial loss across network users to balance the protocol’s books.

“Bitcoin is hard money and can’t be minted without costs,” Blockstream stated, emphasizing its commitment to the underlying economic principles of the digital currency. “Bitcoin doesn’t haircut users to pay a ransom.” As of Friday, the benchmark cryptocurrency was trading near $79,062.

Blockstream has warned the perpetrators that it will move from negotiation to active prosecution if the assets are not returned immediately. The infrastructure firm is working with blockchain forensics firms, major cryptocurrency exchanges, and international law enforcement agencies to trace the stolen funds and identify those behind the exploit. “Transactions do not disappear, and neither does the evidence they leave behind,” Blockstream warned. “Return the bitcoin.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *