BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
Scam WatchBearish

Sidechain Operator Refuses $46M Hacker Ransom Demand

An infrastructure provider is refusing to pay a nearly $46 million ransom following a massive sidechain exploit, rejecting the attackers' claim to a "white-hat" bug bounty.

On September 6, attackers manipulated a software vulnerability on Blockstream's Liquid Network, a sidechain where users lock Bitcoin for faster transactions. The flaw allowed them to create unbacked Liquid tokens (L-BTC). They subsequently used SideSwap's peg-out infrastructure to withdraw almost 4,000 real Bitcoin from Liquid's federation reserves. Because the federation signing keys were never stolen, the draining transaction cleared normally.

The stolen funds were worth approximately $320 million at the time, removing about 95% of the Liquid Federation's 4,200 Bitcoin reserves.

After Blockstream patched the vulnerability with a software update called Elements v23.3.4, the perpetrators returned about 85% of the taken assets. On September 7, roughly 3,400 Bitcoin was transferred back. However, the attackers retained 598.5 Bitcoin, valued at roughly $46 million at current prices, demanding it be treated as a retroactive bug bounty.

Refusing the White-Hat Label

Blockstream flatly rejected the proposal, stating it will explore all available legal options if the remaining funds are not surrendered. "We will not pay for the return of stolen property," the company declared.

Sidechain Operator Refuses $46M Hacker Ransom Demand
We will not pay for the return of stolen property,

The firm emphasized that draining a network and holding the funds hostage does not qualify as security research. "Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft," Blockstream stated.

This hardline stance breaks with an emerging crypto industry habit of allowing self-declared hackers to keep a slice of their haul. Following a $190 million exploit in 2022, the Nomad bridge publicly offered attackers 10% to send the rest back. In contrast, Blockstream's refusal mirrors actions by Kraken, which accused security researchers of extortion in 2024 after they withheld $3 million. Ledger Chief Technology Officer Charles Guillemet also recently argued that attackers who empty reserves and then initiate contact are not conducting legitimate security research.

Recovery Efforts Continue

Following the software patch, block production on the Liquid sidechain resumed. According to Samson Mow, Blockstream's former chief strategy officer, network transactions are processing normally again. However, Mow noted that circulating L-BTC is currently only about 85% backed due to the outstanding 598.5 Bitcoin.

Blockstream stressed that rewarding hackers with massive payouts sets a dangerous standard. "We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation," the firm explained. Furthermore, the company noted that "Bitcoin doesn’t haircut users to pay a ransom."

While recovery now relies on chain forensics, exchanges, and law enforcement, Blockstream left a final warning for the unidentified actors: "Transactions do not disappear, and neither does the evidence they leave behind." Despite the threat of legal escalation, the firm added that "there is still an opportunity to resolve this responsibly" without further action.

← All stories