cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Blockstream Rejects Liquid Exploit Ransom as Bitcoin Recovery Stalls

Blockstream Rejects Liquid Exploit Ransom as Bitcoin Recovery Stalls

Van Thanh Le

Van Thanh Le

PublishedSep 12 2026

UpdatedSep 12 2026

1 hour ago3 minutes read
Robot rejects Liquid exploit ransom for Blockstream recovery efforts

Company disputes hackers’ white-hat claim after most funds are returned

TL;DR

  • Blockstream rejected the Liquid exploiters’ bounty demand and told them to return the remaining Bitcoin.
  • The exploit stemmed from a range-proof verification caching vulnerability in Elements, not compromised federation keys.
  • Liquid restored block production and transactions after deploying an emergency software update, while peg-outs remained disabled.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Blockstream on Sept. 11, 2026, rejected payment terms demanded by the actors behind the Liquid Network exploit, saying it would not pay for the return of stolen property as about 598.5 BTC remained outstanding. Blockstream also rejected the actors’ description of their actions as white-hat security work and said it would work with law enforcement, exchanges, service providers and forensic specialists if the remaining funds were not returned.

Blockstream said it had engaged with the exploiters in good faith while seeking recovery of the funds but refused their financial conditions. Its message was blunt: “Return the bitcoin.” The company said retaining assets and conditioning their return on compensation could not be treated as responsible disclosure.

“Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft,” Blockstream said.

tweet-2098281867908690394.webp

Blockstream also framed its refusal as a matter affecting open-source software developers more broadly. “We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation,” the company said.

The company thanked the Bitcoin community for its support and said the exploiters could still resolve the dispute by voluntarily returning the assets. Blockstream warned that blockchain activity would remain traceable, saying: “Transactions do not disappear, and neither does the evidence they leave behind.”

Blockstream added: “We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”

Exploit Created Unbacked LBTC Through Elements Vulnerability

Liquid’s Sept. 8 incident findings attributed the exploit to a vulnerability involving the caching of range-proof verifications in Elements, the software underlying the Liquid Network. The flaw allowed unbacked LBTC to be created without corresponding Bitcoin held in reserve before the assets were converted into real BTC through Liquid’s withdrawal infrastructure.

Liquid said network operators were not hacked and no keys were compromised. The distinction separates the incident from a direct compromise of federation signing infrastructure: the vulnerability allowed invalid LBTC to enter a process that ultimately resulted in valid Bitcoin withdrawals.

tweet-2097404704028545175.webp

The exploiter used SideSwap, a Liquid Network wallet and trading platform, to move from the unbacked LBTC into BTC. SideSwap is a Liquid Federation member and holds a peg-out authorization key, allowing the illegitimate LBTC to be converted through what appeared to be a standard peg-out process.

The chronology and principal figures were as follows:

Date or metric Figure Detail
Around Sept. 6, 2026 Roughly 4,000 BTC Liquid paused operations after roughly the same amount of unbacked LBTC was created and converted into BTC.
Incident-time valuation Approximately $320 million Approximate value assigned to the Bitcoin involved at the time.
Sept. 7 Approximately 3,400 BTC The exploiter returned most of the Bitcoin after calling for the bug to be fixed first.
Outstanding amount, rounded account About 598 BTC A separate supplied figure rounded the remaining balance to this amount.
Sept. 9 Elements v23.3.4 Emergency software version deployed during recovery.
Sept. 10 Block production and transactions resumed Peg-outs remained disabled while recovery continued.
Bounty demand 10% The exploiter demanded compensation funded by Blockstream.
Exploiter’s security-cost claim $1.5 million, “maybe even 0” Claimed amount Blockstream had spent securing the assets.
Exploiter’s asset-value claim $5 billion Claimed amount of assets being secured.
Threatened holder impact 15% loss Loss the exploiter claimed Liquid holders could face if the demand was rejected.
Approximate recovery share 85% Calculated from the approximate returned and original Bitcoin amounts.
Implied incident-time BTC value About $80,000 per BTC Calculation using the approximate Bitcoin amount and contemporaneous valuation.
Implied value of the retained balance Roughly $47.9 million Calculated on the same approximate valuation basis.

Before returning most of the funds, the exploiter posted an onchain message telling Blockstream to “fix the bug first” and said “most” of the Bitcoin would be returned afterward. The majority of the funds were subsequently sent back as the recovery process advanced.

Exploiter Demanded Bounty After Returning Most Funds

A later OP_RETURN message demanded that Blockstream fund a bounty from its own money. Jan3 CEO and former Blockstream chief strategy officer Samson Mow publicly shared the message.

tweet-2097785361342845125.webp

“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the exploiter wrote.

Blockstream rejected that framing, saying the retention of assets while demanding compensation amounted to theft rather than responsible security disclosure. The company’s objection covered both the financial demand and the principle of forcing open-source developers to personally fund the recovery of assets after an exploit.

Recovery work continued independently of the dispute. Liquid initially restarted by producing empty blocks while transactions and Bitcoin transfers remained suspended. Transactions later resumed as the network moved further through the recovery process, but peg-outs stayed disabled “while the final stage of recovery continues.”

Restoring the BTC/LBTC reserve remained part of that process because the vulnerability had allowed unbacked LBTC to be converted into actual Bitcoin. Returning most of the withdrawn funds repaired most of that reserve deficit, but the retained balance prevented the recovery from being complete.

Blockstream said failure to return the remaining Bitcoin would trigger broader recovery efforts involving law enforcement, centralized exchanges, service providers and blockchain-forensics specialists. The company said it would use the permanent transaction trail to pursue the funds and identify the responsible actors.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.18
© 2017 - 2026 COIN360.com. All Rights Reserved.