The company behind Bitcoin's Liquid sidechain says paying off the people holding its stolen coins would set a precedent it's not willing to create — even with millions still missing.
Blockstream said on Sept. 11 that it will not pay any bounty to recover the roughly 598.5 BTC, about $47 million, still missing after an exploit drained its Liquid sidechain on Sept. 6. “It is not white-hat activity. It is theft,” the company wrote on X, rejecting the attackers’ own characterization of the hack and their subsequent demand for a cut of the stolen funds.
Screenshot: Blockstream’s Post on X
How the Liquid exploit actually happened
The mechanics behind the theft are more unusual than a typical hack, and they didn’t involve anyone’s private keys getting stolen. Liquid, Blockstream’s Bitcoin sidechain, launched in 2018, uses something called confidential transactions to hide transfer amounts while still letting the network confirm nothing’s been forged.
That verification relies on cryptographic range proofs, which are expensive to compute, so Liquid’s software, Elements, caches the results to avoid redoing the work.
That cache turned out to be the weak point. According to independent technical breakdowns of the Elements code published after the incident, the cache key didn’t account for which asset or spending conditions a proof was tied to.
That gap meant a proof already verified in one context could get reused to validate a transaction it was never meant to cover, effectively letting the attacker mint Liquid Bitcoin that had no real Bitcoin backing it.
The unbacked coins then moved out through SideSwap, a federation member that processes withdrawals; SideSwap’s own authorization key was never compromised, it simply had no way to tell the fraudulent L-BTC apart from the real thing. By the time the withdrawal was confirmed on Sept. 6, roughly 4,000 of the wallet’s 4,200 BTC, about 95% of Liquid’s entire reserve, was gone.
From negotiation to a direct threat
What followed looked less like a standard ransomware standoff and more like a public back-and-forth conducted entirely on-chain. The people behind the withdrawal, describing themselves as white-hat hackers, wrote messages to Blockstream directly into Bitcoin transaction data, telling the company to patch the vulnerability and confirm every affected node before they’d send anything back.
Blockstream cryptographically confirmed the fix was live, and on September 7, the attackers sent 3,400 BTC back into the federation’s holdings, which is about 85% of what they’d taken.
The remaining stake didn’t come back quietly. Cointelegraph reported that the attackers later shifted their position entirely: hand over a tenth of the stash’s value out of Blockstream’s own treasury, or Liquid token holders would absorb a 15% loss instead. That ultimatum surfaced in an on-chain message shared publicly by Samson Mow, the Jan3 CEO and a former Blockstream chief strategy officer.
Screenshot: Samson Mow’s Post on X
Blockstream draws a hard line
Blockstream’s response treated that shift as confirmation that this was never a security disclosure to begin with. The company said its earlier back-and-forth with the attackers, aimed at protecting user funds, shouldn’t be read as accepting either the original withdrawal or the bounty demand that came after.
It argued that caving to the demand would put every open-source Bitcoin developer at risk of the same shakedown anytime someone finds a bug in code they wrote for free. As the company put it in its statement, this isn’t white-hat activity, it’s theft, plain and simple.
Blockstream also gave a nod to the wider community of coders, cryptography specialists, and bug hunters who’ve been patching holes across Bitcoin’s software stack in the wake of the incident, and pointed to a broader trend it’s watching: as AI tools make code auditing faster, teams across the ecosystem are spending more time hunting for weaknesses in each other’s software before someone else does.
What happens to the missing Bitcoin now
With roughly 598.5 BTC still unaccounted for, Blockstream says the door isn’t fully closed, whoever’s holding it can still return the coins and step away from this fight. If that doesn’t happen, the company says it’ll coordinate with police agencies, exchanges, and blockchain forensics specialists to trace the coins, leaning on the fact that Bitcoin’s public ledger keeps a permanent record no matter how many wallets the funds pass through.
That kind of tracing has worked before. A similar approach paid off after August’s Coldcard hardware-wallet exploit: Galaxy Research tracked down that the bulk of the roughly 1,789 BTC taken there, 1,561 of it, was still sitting untouched in traceable addresses, which the firm passed along to exchanges and compliance teams. Blockstream appears to be betting the Liquid exploit plays out the same way, and it’s made clear it isn’t interested in shortcutting that process with a payout.
Not every project in this position has taken the same stance. After a separate August incident exposed admin credentials on an LND node running BTCPay Server, that community actually organized a modest recovery bounty, a tenth of whatever got recovered, topping out at 3 BTC total, as an incentive to bring funds back.
Blockstream’s decision not to follow a similar path on a hack roughly 200 times larger says something about where it’s drawing its own line between rewarding good-faith disclosure and negotiating with a $47 million threat.