Table of Contents

Blockstream Rejects Ransom Demand for 600 BTC From Liquid Exploit 

Blockstream logo 

Blockstream has rejected a demand for a 10% bounty from the actors behind the Liquid Network exploit, refusing to pay for the return of the roughly 598.5 BTC that remains outstanding.

The dispute follows an exploit on Sept. 6 that resulted in approximately 4,000 BTC being withdrawn from Liquid’s reserves. Around 3,400 BTC was later returned after Blockstream confirmed that the underlying software vulnerability had been fixed, leaving approximately 598.5 BTC still under the attackers’ control.

Blockstream said it had attempted to secure the return of the remaining funds but rejected the terms proposed by the attackers.

“Taking assets without authorization and withholding their return is a crime, not responsible disclosure,” the company said. “It is not white-hat activity. It is theft.”

KEY TAKEAWAYS

  • About 598.5 BTC remains outstanding after roughly 4,000 BTC was taken from Liquid.
  • The attackers returned 3,400 BTC after the underlying vulnerability was patched.
  • Blockstream rejected a demand for a 10% bounty to recover the remaining Bitcoin.
  • Liquid has restored block production and transactions, but peg-outs remain disabled.
  • Blockstream said it will work with law enforcement, exchanges and forensic specialists if the Bitcoin is not returned.

HOW THE LIQUID EXPLOIT HAPPENED

The incident did not involve the compromise of Liquid’s federation keys, according to the network’s investigation. Instead, the vulnerability was found in the Elements software used by Liquid. The flaw involved the caching of range proof verification results. Range proofs are part of Liquid’s confidential transaction system and help nodes verify that transactions do not create assets without the required backing.

The exploit allowed attackers to create roughly 4,000 unbacked LBTC. Those tokens were subsequently converted into real BTC through Liquid’s normal peg-out process using SideSwap, a Liquid Federation member with a peg-out authorization key. SideSwap said its own systems and authorization key were not compromised.

Liquid had approximately 4,200 BTC in its reported reserves before the incident, meaning the withdrawal represented most of the network’s available Bitcoin backing. After the exploit, the attackers contacted Blockstream through Bitcoin’s onchain messaging system and said they would return most of the funds once the vulnerability was fixed.

Blockstream subsequently confirmed that affected bridge nodes had been patched. The attackers then sent 3,400 BTC back to the Liquid Federation wallet, leaving approximately 598.5 BTC in an address under their control.

BLOCKSTREAM REJECTS THE 10% DEMAND

The remaining Bitcoin became the subject of a dispute over whether the attackers should receive a reward for returning the funds. In an on-chain message, the attackers demanded 10% of the recovered funds as a bug bounty. They argued that Blockstream should pay the bounty from its own resources and warned of potential losses for Liquid holders if the demand was not met.

Blockstream rejected that proposal, saying it would not establish a precedent where open-source developers could be required to pay large sums after an unauthorized asset withdrawal. The company also said that if the Bitcoin is not voluntarily returned, it will cooperate with law enforcement, exchanges, service providers and forensic investigators to trace the funds and identify those responsible. The remaining 598.5 BTC was valued at roughly $47 million when the dispute was reported. A subsequent on-chain investigation published later in September found that the Bitcoin had remained unmoved at that point.

LIQUID RESUMES OPERATIONS

The exploit temporarily halted activity on Liquid while developers investigated the vulnerability and prepared a software fix. An emergency Elements v23.3.4 release was deployed on Sept. 9. Liquid subsequently resumed block production and transactions on Sept. 10. However, peg-outs remained disabled as a precaution while recovery work continued.

The distinction matters for users because transactions on the sidechain can resume while the mechanism for converting LBTC back into Bitcoin remains restricted. The incident also highlights the security risks that can exist in infrastructure built around Bitcoin. The Bitcoin network itself was not exploited. Instead, the vulnerability occurred within the software and mechanisms responsible for representing and moving Bitcoin through Liquid.

CONCLUSION

Blockstream’s refusal leaves roughly 598.5 BTC unresolved after most of the funds taken during the Liquid exploit were returned. The immediate focus is now on whether the remaining Bitcoin will be voluntarily returned and whether investigators can trace the funds if it is not. For Liquid, restoring normal operations while keeping peg-outs disabled provides another stage of recovery after the software vulnerability was patched.

The incident demonstrates how vulnerabilities in sidechains, bridges and asset conversion mechanisms can expose significant amounts of cryptocurrency even when the underlying Bitcoin blockchain remains operational.

Disclaimer: This article is intended solely for informational purposes and should not be considered trading or investment advice. Nothing herein should be construed as financial, legal, or tax advice. Trading or investing in cryptocurrencies carries a considerable risk of financial loss. Always conduct due diligence before making any trading or investment decisions.

Trade with proof of Reserves

UEEx publish monthly audits and third party verification on every listed market.

COLD STORAGE
0 %
AUDIT
Monthly 0

UEEx Weekly Digest

Market analysis and security alerts, read by 10,000 traders

UEEx Weekly Digest

Market analysis, trading strategies, futures insights, and security alerts delivered weekly. Read by 10,000+ crypto traders.

No spam. Unsubscribe anytime