0x53801c075380…53801c0a

ConfirmedSecurity643 vB179 sat/vB3 min decode

Blockstream Refuses Ransom for 598 BTC Held by Liquid Exploiters

Blockstream has refused to pay a ransom for 598.5 Bitcoin worth roughly $47 million still held by September's Liquid Network exploiters, ending negotiations and opting for law-enforcement tracing.

Outputs

  1. Attackers drained roughly 4,000 BTC (~$320M at the time) from the Liquid federation reserve on September 6 by exploiting a flaw in range proof verification tied to peg-outs.

  2. Attackers returned approximately 3,400 BTC on September 7 but kept 598.5 BTC (~$47M) at an address they still control.

  3. Blockstream issued the Elements v23.3.4 patch within roughly ten hours of discovery; block production resumed Thursday but peg-outs remain disabled.

  4. Former Blockstream CSO Samson Mow noted L-BTC is only about 85 percent backed while the 598 BTC gap remains with the attackers.

  5. The federation wallet held roughly 4,200 BTC before the attack, meaning the exploit stripped out about 95 percent of reserves.

Blockstream has refused to pay a ransom covering 598.5 Bitcoin, worth roughly $47 million, still held by the parties behind September's Liquid Network exploit, according to Decrypt reporting published Friday. The decision ends a multi-day negotiation and shifts the case toward law-enforcement and exchange-level tracing rather than settlement.

The breach hit the Liquid federation reserve on September 6, when attackers drained close to 4,000 BTC — then valued at roughly $320 million — by exploiting a flaw in how Liquid nodes verified range proofs during peg-outs.

The vulnerability sat in the verification logic tied specifically to peg-out transactions, not in general wallet-to-wallet transfers on the sidechain. Attackers minted unbacked Liquid Bitcoin (L-BTC), submitted the phantom tokens through SideSwap's peg-out infrastructure, and received genuine BTC from the federation's reserves in return. Range proofs normally attest that the Bitcoin locked behind minted L-BTC actually exists; the flaw allowed attackers to fabricate those attestations and walk out with federation BTC against tokens with no corresponding backing.

The federation wallet held roughly 4,200 BTC before the attack, meaning the exploit stripped out about 95 percent of those reserves. On September 7, attackers returned approximately 3,400 BTC, leaving 598.5 BTC unmoved at an address they still control.

What is Blockstream's position?

Blockstream characterized the incident as straightforward theft. "Taking assets without permission and refusing to return them is a crime," the company wrote, rejecting the attackers' attempt to frame the exploit as responsible disclosure. Blockstream refused to recognize the attackers' claim to white-hat status outright.

The attackers had demanded ten percent of the reserve as a bug bounty and warned that a refusal would leave holders absorbing a fifteen percent loss. They also embedded a Bitcoin transaction message claiming Blockstream spent only $1.5 million, possibly less, to secure assets worth roughly $5 billion. During the negotiation window they cited standard responsible-disclosure norms; Blockstream countered that those norms require returning stolen assets as a precondition.

Blockstream rejected the terms in full. The company said it would not accept responsibility for paying a ransom that exceeds its own economic stake in an open-source project built for the Bitcoin community, and ruled out covering the shortfall by reducing user balances.

What is the current state of the sidechain?

Blockstream issued a patch — Elements v23.3.4 — within roughly ten hours of discovering the problem. Block production on Liquid resumed Thursday, though peg-outs remain disabled while recovery continues.

Former Blockstream chief strategy officer Samson Mow noted that L-BTC is currently only about 85 percent backed while the outstanding 598 BTC remains in the attackers' control. The shortfall amounts to roughly fifteen percent of the pre-attack reserve — matching the loss figure they referenced in their negotiation message.

What enforcement channels is Blockstream pursuing?

The company said it would pursue law enforcement, exchanges, and forensic specialists if the funds are not returned. Blockstream warned that Bitcoin's public blockchain preserves a permanent record of every transaction, telling the attackers that the evidence does not disappear.

Blockstream left the door open for voluntary return without further escalation. The company's statement closed with a direct instruction to the attackers: return the bitcoin.

What's the next operational milestone?

Online, some observers pushed back on Blockstream's position, arguing the company bore responsibility for the vulnerability that enabled the attack. Blockstream has not disclosed whether exchanges have begun freezing related accounts or whether formal complaints have been filed with law enforcement.

The next concrete milestone will be the reactivation of Liquid peg-outs, suspended since the attack and unlikely to reopen while the 598.5 BTC gap remains unfunded or unrecovered — a constraint that leaves federation members facing the choice between recapitalizing the reserve unilaterally or absorbing continued user-side redemption delays.

via decrypt.co (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles