Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$77,086▼ 0.41%ETH$2,490▼ 2.04%SOL$100.44▼ 1.51%TOTAL CRYPTO$2.62T▼ 4.16%S&P 5007,656.98▼ 0.92%NASDAQ26,333.04▼ 0.43%DOW52,573.29▼ 2.27%GOLD4,408.90▲ 1.04%WTI100.05▲ 23.14%BRENT104.61▲ 20.14%EUR/USD1.1601▲ 0.48%USD/JPY153.55▼ 3.52%DXY99.10▼ 0.87%
Crypto

Blockstream Refuses Ransom as Red Team Claims Warnings Ignored

Blockstream will not pay the 598.5 BTC ransom from the Liquid Network exploit, and Bitcoin Red Team says the company ignored security warnings before the attack.

Pexels – DS stories

Blockstream refused on September 11 to pay the 598.5 BTC ransom demanded by the hackers who drained its Liquid Network, and now a security research group says the company ignored warnings about the very bug that made the heist possible.

The dispute has turned a $320 million exploit into a public argument about who is to blame. Calle, co-lead of the volunteer group Bitcoin Red Team, said Blockstream received emails from the group before the September 6 exploit and did not act on them. “Turns out it only costs you 600 BTC to ignore security reports,” he wrote, linking the unpaid balance to the earlier warning. Samson Mow, Blockstream’s chief strategy officer, rejected the claim in a public exchange, saying no emails were ignored.

The row began when attackers pulled roughly 4,000 BTC, worth about $320 million at the time, out of the federation wallet that backs L-BTC, the token of the Liquid sidechain. Liquid is a federated Bitcoin sidechain used by exchanges for fast settlement. Every L-BTC is supposed to be matched one-for-one with bitcoin locked in a shared wallet controlled by a group of functionaries. The exploit left that promise broken for several days.

How the exploit worked

Blockstream’s incident report says no private keys were compromised. Instead, the attackers exploited how nodes running the open-source Elements software cached range-proof verifications. That flaw let them create about 4,000 L-BTC with no bitcoin behind it, then push the unbacked tokens through the standard peg-out process, which released real bitcoin from the federation reserves. The funds moved through SideSwap’s Peg-out Authorization Key, though no SideSwap key or wallet was compromised.

The wallet held about 4,200 BTC before the attack and just 197 BTC after. Exchanges paused L-BTC deposits and withdrawals, and the network stopped producing blocks for four days. Block generation resumed on September 10 with peg-outs still disabled, after an emergency software release, Elements v23.3.4, was deployed on September 9.

The attackers returned 3,400 BTC on September 7 and 8 after on-chain negotiations with the company. They kept the remaining 598.5 BTC, about $47 million at current prices, and demanded a 10 percent bounty paid from corporate funds. Messages sent through bitcoin transactions warned that refusal would cost Liquid users more.

Blockstream called the demand theft. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft,” the company said in a statement. It added that paying would set a precedent no open-source project could afford: “We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation.” The company says it will work with law enforcement, exchanges and blockchain forensics firms to recover the rest.

Adam Back points at a botched fix

Blockstream founder Adam Back linked the exploit to an incorrect fix for an earlier, separate vulnerability, saying a patch meant to close one hole opened another. The functionary codebase federation members run had not been updated in more than two years before the incident, which reporting from Blockhead flagged as a contributing factor.

The Bitcoin Red Team claim sharpens that picture. The group, 16 volunteers including developer Calle and AnchorWatch CEO Rob Hamilton, runs AI-assisted security reviews of Bitcoin ecosystem projects. In an August audit it reported nearly 5,000 potential issues across 390 repositories, 720 of them rated high or critical. Calle says the group emailed Blockstream about the Liquid vulnerability before September 6. He has promised a full account of the disclosure process once Blockstream restores normal operations and publishes its post-incident report.

Mow pushed back on the accusation and on the group’s methods more broadly. He warned against trusting AI-generated security reports blindly, arguing that unverified fixes can introduce new vulnerabilities, and criticized researchers he says prioritize influence over protecting bitcoin. The two camps now disagree publicly about whether a warning existed, whether it was specific enough to act on, and whether AI-assisted auditing produces findings worth taking seriously.

Liquid launched in 2018 as a faster, more private settlement layer on top of bitcoin, aimed at exchanges and institutional traders. Its federation model relies on a consortium of functionaries who collectively manage the peg between bitcoin and L-BTC. That design trades miner-based security for speed and confidentiality, and the September exploit showed what happens when the software behind that trade is stale.

The company’s refusal also puts pressure on exchanges that listed L-BTC. Several paused deposits and withdrawals during the incident and have not said when they will reopen them. Trading venues that hold L-BTC in custody face their own accounting questions about whether the federation’s reserves will be topped back up to one-to-one.

Blockstream has not given a date for restoring full peg-outs. Until it does, Liquid remains in a partial state: blocks are being produced, but the core promise that lets users move value back to bitcoin mainnet is restricted.

What it means for sidechains

The incident is a setback for the federated sidechain model. Liquid’s security depends on a consortium of functionaries rather than bitcoin miners, and the exploit showed that a software bug, not a stolen key, can break the one-to-one backing promise. Other Liquid assets, including issued stablecoins and tokenized assets, were not directly affected, and the bitcoin mainnet was untouched.

Recovery is incomplete. The network produces blocks again, peg-outs remain restricted, and about 15 percent of the stolen funds sit with attackers who insist they are researchers owed a bounty. Holders of L-BTC are waiting to learn whether the federation will make them whole from its own reserves or absorb a permanent loss.

For exchanges and institutions using Liquid for settlement, the question is whether the federation model can be audited well enough to trust. For open-source projects across crypto, the dispute sets a test case: if a company refuses to pay for the return of stolen funds, attackers who call themselves white hats have little incentive to return anything at all.

SourcesBlockstream incident statements and status page; CoinDesk; The Register; Coin Edition; Crypto Briefing
Share: X