Blockstream Refuses Ransom for Return of $47M in Bitcoin From Liquid Hack
- Liquid Network suffered a $320 million exploit via a range proof caching vulnerability in Elements software, allowing unbacked LBTC creation.
- The incident halted the Liquid Network, exposing systemic risks where multiple signers can approve withdrawals based on invalid internal states.
- Purported white-hat hackers exploited a caching vulnerability in Liquid Network's transaction validation to mint unbacked L-BTC, draining ~4,000 BTC from federation reserves.
- Blockstream has refused to pay a 10% ransom demanded by the actors who exploited the Liquid Network, threatening legal action against the $47 million in withheld BTC.
- STOKR confirms that the Liquid Network bug affected only on-chain transfers, leaving digital securities holdings intact.
On September 6, 2026, the Liquid Network halted transactions after approximately 4,000 BTC were withdrawn, valued at roughly $320 million, from its federation-controlled reserves. This withdrawal represented about 95% of the network's total reserves, which stood at approximately 4,200 BTC prior to the incident . The BitcoinBTC-- base layer and consensus rules were not compromised; the incident was isolated to the Liquid sidechain infrastructure .

The attack exploited a vulnerability in the Elements software, specifically a range-proof verification cache bug . This flaw allowed attackers to generate invalid L-BTC tokens that the system accepted as legitimate . These fraudulent tokens were then submitted through SideSwap’s Peg-out Authorization Key (PAK) . SideSwap correctly processed the request, burned the L-BTC, and instructed the federation to release the corresponding BTC . The federation, operating on an 11-of-15 multisig model, authorized the release of 3,996 BTC .
Crucially, neither the federation keys nor SideSwap’s PAK were compromised; the failure stemmed from software validation issues upstream of the multisig signature . The incident occurred despite a code change titled "fix: range proof cache bind to asset and scriptpubkey" being merged into the Elements repository days prior . However, this fix had not yet been released or deployed to production nodes, highlighting the "patch gap" where vulnerabilities remain exploitable between code publication and system deployment .
What happened during the Liquid Network exploit and how was it executed?
Liquid Network uses range proofs to ensure users cannot create assets out of thin air . To optimize performance, the software caches successful verification checks . The hackers exploited a flaw in the system used to identify cached checks, allowing them to submit invalid data that pointed to a previously approved cached result . This bypassed full verification, enabling the creation of unbacked L-BTC tokens which were then exchanged for real BTC via the peg-out process .
The exploit relied on a flaw in the network's transaction validation software, specifically within the caching mechanism for Confidential Transactions' range proofs . Independent analysis suggests the vulnerability may have been discoverable through "patch diffing," where attackers analyze public code changes to reverse-engineer weaknesses . Additionally, former Blockstream developer Gregory Maxwell raised concerns that the attempted fix itself might have introduced a hash-collision vulnerability, though this remains unconfirmed .
Why did the Liquid Network pause and what was the immediate impact on the ecosystem?
Following the incident, Liquid Network disabled its bridge nodes and suspended L-BTC deposits and withdrawals across exchanges . The attackers, who identified themselves as 'white hats,' communicated with Blockstream on-chain, demanding that the vulnerability be patched before returning the funds . Liquid’s bridge nodes remain disabled while the federation works to identify the flaw, distribute the fix, and reconcile the reserve accounting .
For digital securities platforms like STOKR, the impact is limited to network availability . Digital securities holdings are unchanged, and balances are correct in holders' wallets . No unauthorized issuance of STOKR-issued assets occurred . The AMP infrastructure for issuing and managing digital securities is operational and uncompromised . Digital securities are not backed by the federation peg wallet, the Bitcoin held in it, or L-BTC; the assets and arrangements backing each instrument sit off the Liquid Network and are unaffected .
The register of holders is held on STOKR infrastructure rather than on the network and remains unaffected . What is affected is the ability to transfer digital securities on-chain, deposit them, or withdraw them from Biftinex Securities . Settlement of redemptions requiring on-chain transfer is deferred until transfer functionality is restored . STOKR continues to monitor the Liquid Network and relevant on-chain addresses while onboarding and reporting operations run normally .
How did Blockstream respond to the white-hat hackers and the remaining funds?
Blockstream released an emergency update (Elements v23.3.4) to fix the vulnerability . Subsequently, the actors returned 3,400 BTC to the federation . Approximately 598.5 BTC remains outstanding, which the attackers retained as a self-appointed bug bounty . The attackers had previously demanded a reward equal to 10% of the withdrawn amount to be paid from Blockstream’s own funds, warning that liquidators could face losses of around 15% otherwise .
Blockstream has publicly refused to pay a ransom to the party that withdrew approximately 4,000 BTC from the Liquid Network reserves . The company stated that taking assets without permission and refusing to return them constitutes theft, not responsible vulnerability disclosure . The incident involved a vulnerability in the Elements software that allowed the creation of unbacked L-BTC tokens, which were then used to withdraw real bitcoin via SideSwap .
Blockstream emphasized that it negotiated with the involved parties in good faith but will not agree to their demands . The company announced it will collaborate with law enforcement, cryptocurrency exchanges, service providers, and blockchain forensics specialists to recover the remaining funds . Blockstream noted that all transactions on the Bitcoin network are public, ensuring that evidence related to the incident is preserved on-chain .
Blockstream has refused to pay a 10% ransom demanded by the actors who exploited the Liquid Network, threatening legal action against the $47 million in withheld BTC . The company distinguishes between responsible vulnerability disclosure and theft, asserting that refusing to return stolen assets is a crime . They have threatened to involve law enforcement and blockchain forensics specialists if the funds are not returned voluntarily.
Liquid Network block production resumed on September 10, 2026, at 10:00 UTC . Peg operations remain suspended while the BTC/L-BTC reserve is restored . Recovery depends on patching every affected node, returning the funds, and proving that reserves again match legitimate outstanding L-BTC one-for-one .
The incident raises significant investor and operational questions regarding the security of sidechain peg-outs, the reliance on binary authorization systems for large-value transactions, and the risks associated with public open-source development models where fixes may inadvertently expose attack vectors before they are mitigated .
Blending traditional trading wisdom with cutting-edge cryptocurrency insights.
Latest Articles
Stay ahead of the market.
Get curated U.S. market news, insights and key dates delivered to your inbox.



Comments
No comments yet