Morning Edition · Saturday, September 12, 2026Published at 1:48 AM EDT · New York
The company says it will involve law enforcement and exchanges instead of paying. Liquid bitcoin has resumed trading with on-chain reserves covering 85.15% of supply.

Blockstream has told the group that drained its Liquid sidechain that it will not pay for the return of the remaining coins. "Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft," the company said in a statement reported by Bitcoin Magazine and circulated in French-language crypto channels.
The mechanics of the attack are now documented. On September 6 the attackers exploited a range-proof verification cache defect in Elements, the software Liquid runs, and minted roughly 4,000 Liquid bitcoin (L-BTC) that the network accepted as fully collateralized. They then pegged out about 3,998.5 real bitcoin from the federation wallet, worth roughly $320 million at the time. This was not a smart-contract logic bug in an application. It was a failure in the cryptographic check that is supposed to make an unbacked mint impossible, which is the single assumption the entire peg depends on.
The group described itself as a white hat, sent encrypted vulnerability details, and demanded that every node be patched before it would return anything. After Blockstream replied with a signed confirmation, 3,400 bitcoin came back on September 7. The attackers kept 598.5 bitcoin, worth about $47 million, and then demanded a 10% bounty paid from Blockstream's own funds, warning through on-chain messages that Liquid holders would otherwise absorb a 15% loss. Blockstream said it will not accept a precedent in which open-source developers pay ransoms far larger than their economic stake in a network, and that it plans to involve law enforcement, exchanges, service providers and forensic specialists.
The shortfall is visible on-chain. A September 10 snapshot put L-BTC backing at 85.15% while federation peg-outs stayed suspended, and trading resumed on a venue where live depth is unmeasured. Holders can therefore transact a token that is currently not fully redeemable, at a price set by a market with no disclosed liquidity. Blockstream has said it intends to cover the shortfall, which converts a protocol failure into a corporate credit exposure.
The episode also challenges the informal norm that returning most of a theft earns a negotiated cut. Blockstream benefits from refusing, because paying would price every future vulnerability against its balance sheet. The attackers benefit from the norm holding, because it converts an exploit into a billable service. No third party has verified the group's identity or intent.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
Blockstream gains from refusing, because paying would set a public price for every future vulnerability found in its code, while the attackers gain if the informal convention of a negotiated cut hardens into an expectation, and the exchanges and traders who treated L-BTC as equivalent to bitcoin carry the residual loss until the shortfall is funded.
The refusal, the September 6 range-proof cache defect, the 3,400 bitcoin return and the 598.5 bitcoin still held are corroborated by The Block and crypto.news, but the 85.15% coverage figure is one third-party reading of an explorer endpoint rather than an audited reserve statement, and nobody outside the parties has established the group's identity, whether it had prior knowledge of the defect, or whether Blockstream's pledge to absorb the $47 million is actually funded.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
A federated sidechain concentrates counterparty risk in one operator and one codebase, and Liquid users are now exposed on both counts: the token is 85% backed on-chain, redemptions are frozen, and full recovery depends on a private company choosing to absorb a $47 million loss. The wider channel runs through bitcoin-adjacent infrastructure generally, because exchanges and traders who used Liquid for fast settlement must reprice the assumption that a two-way peg is equivalent to holding bitcoin.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · CryptoSlate · Polylog editors
Comments
0No comments yet.