Blockstream Refuses Ransom After Liquid Bitcoin Exploit
Blockstream publicly refused to pay a ransom for roughly 598.5 BTC (about $47 million) still held by attackers after an exploit on the Liquid Network sidechain that drained around 4,000 BTC, worth roughly $320 million, on Sunday. The attackers returned 3,400 BTC (about 85%) on Monday, and Liquid resumed producing blocks and processing transactions on Thursday with peg-outs still disabled as a precaution.
This is one of the largest confirmed losses on a Bitcoin sidechain, and the reserve backing Liquid's L-BTC fell as low as 197 BTC, raising questions about the security assumptions of federated bridges that many exchanges and traders rely on for fast, confidential Bitcoin transfers. Blockstream's refusal to pay also sets a public precedent for how infrastructure developers respond to exploiters demanding bug bounties under threat.
The root cause was a flaw in how Liquid nodes cache range-proof verifications, which let attackers mint unbacked L-BTC and swap it for reserve Bitcoin through SideSwap, a federation member that held a peg-out authorization key; no private keys were reported stolen. Blockstream patched bridge nodes within ten hours and shipped Elements v23.3.4 on Wednesday, and separately warned that scammers are targeting node operators with fake update sites.
rss · The Defiant · · 4 sources
Background, discussion, and references
Market impact
The incident is concentrated in Liquid-adjacent segments: L-BTC liquidity on SideSwap, exchange desks supporting Liquid deposits and withdrawals, and the depleted federation reserve that backs the peg, with peg-outs disabled meaning holders cannot currently redeem L-BTC for base-layer BTC. Broader transmission runs through sentiment toward federated bridges and wrapped-BTC designs, as traders reassess the security assumptions behind sidechain-based bitcoin exposure.
Background
The Liquid Network is a Bitcoin sidechain developed largely by Blockstream that enables faster and more confidential transactions than Bitcoin's base layer. Users move bitcoin onto Liquid through a federation-controlled wallet (peg-in) and receive an equal amount of Liquid Bitcoin, or L-BTC, on the sidechain; peg-out burns L-BTC and releases the locked bitcoin. Anonymous L-BTC amounts are protected by range proofs, a cryptographic proof used in the Elements software that Liquid nodes validate to ensure no one creates coins out of thin air.
References
Tags
#liquid-network#blockstream#bitcoin#exploit#security