Loading prices…
🩸BEARISH

Blockstream Rejects 10% Ransom Demand for 598.5 BTC

Blockstream is calling the 10% demand 'theft, not white-hat disclosure.' The refusal draws a hard line on whether open-source Bitcoin infrastructure pays bug-bounty blackmail at all.

Blockstream has publicly refused to pay the 10% bug bounty an attacker demanded in exchange for returning 598.5 BTC stolen in the Sept. 8 Liquid Network exploit. The bitcoin infrastructure firm told the exploiter in a Friday statement: 'Return the bitcoin,' rejecting any settlement and accusing them of theft rather than responsible disclosure.

The exploit itself stemmed from a vulnerability in the caching of range proof verifications in Elements, the underlying software that powers Liquid. Roughly 4,000 LBTC were created without backing by BTC held in reserve, then converted into native BTC through a standard peg-out via SideSwap, a Liquid Federation member.

Why it matters

Blockstream framed the rejection in moral rather than commercial terms. The company said it 'will not be a party to the precedent' that open-source Bitcoin infrastructure should pay a ransom for return of stolen property, calling the on-chain demand a bug bounty extorted from developers rather than from a paying customer.

The exploiter had previously claimed in an OP_RETURN message that Blockstream spent 'maybe $1.5 million, maybe even 0' securing $5 billion in assets and threatened a 15% loss to holders if the bounty were unpaid. The framing turns the dispute into a test of how the broader Bitcoin developer ecosystem responds to security disclosures that double as extortion.

Market impact

Liquid resumed block production and on-chain transactions on Sept. 10 after Elements v23.3.4 was deployed as a fix. About 3,400 BTC was returned on Sept. 7 after the exploiter initially complied with an earlier on-chain instruction to 'fix the bug first' before 'most' of the funds would be sent back.

The remaining 598.5 BTC now sits in limbo while Blockstream says it will coordinate with law enforcement, exchanges, service providers, and forensic specialists to trace and recover the assets. Peg-outs remain disabled as a precaution while the final recovery stage continues, and the exploit's use of a legitimate peg-out pathway means the funds are mobile and traceable rather than stuck at a known wallet.

Related tokens
$BTC $LBTC

Frequently asked questions

  1. How much BTC is Blockstream trying to recover from the Liquid exploit?

    Blockstream is seeking the return of 598.5 BTC. Roughly 3,400 BTC was returned on Sept. 7 after the attacker initially complied with an earlier on-chain message, leaving about 598.5 BTC outstanding.

  2. What vulnerability caused the Liquid Network exploit?

    The exploit stemmed from a bug in the caching of range proof verifications within Elements, the underlying software that powers Liquid. About 4,000 unbacked LBTC were minted and then converted to BTC via SideSwap's peg-out pathway.

  3. What did the attacker demand from Blockstream?

    The attacker demanded a 10% bug bounty, claiming Blockstream had spent 'maybe $1.5 million, maybe even 0' securing $5 billion in assets. They threatened a 15% loss to holders if the bounty went unpaid.

  4. Is the Liquid Network still operational after the exploit?

    Liquid resumed block production and on-chain transactions on Sept. 10 after Elements v23.3.4 was deployed. Peg-outs remain disabled as a precaution while final recovery efforts continue.

  5. Why is Blockstream refusing to pay the ransom?

    Blockstream says paying would set a precedent that open-source Bitcoin infrastructure can be extorted via bug bounty demands. It has labeled the exploiters' demands 'theft, not white-hat activity,' and plans to work with law enforcement and forensic specialists to recover the funds.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 1h ago
Open original →