Subscribe Now
Trending News

Blog Post

BLOCKSTREAM CALLS THE LIQUID RANSOM “THEFT” — BUT $47 MILLION OF USER BITCOIN IS STILL IN THE HACKER’S WALLET
Featured

BLOCKSTREAM CALLS THE LIQUID RANSOM “THEFT” — BUT $47 MILLION OF USER BITCOIN IS STILL IN THE HACKER’S WALLET 

They drained 95% of a "trusted" sidechain’s vault in one weekend. Then they demanded a 10% ransom – in public, on the Bitcoin blockchain. And now that the company finally called it what it is – theft – the money is still gone, the network is still frozen, and the people who trusted the "institutional-grade" solution are the ones eating the loss.

Read that again. The victims of the $320 million Liquid drain officially refused to pay the ransom this morning. Blockstream’s statement was one sentence of clarity wrapped in a whole lot of nothing for the people actually holding the bag.

"It is not white-hat activity. It is theft."

That’s the part everyone will quote. Here’s the part they won’t – the 598.5 Bitcoin, worth roughly $47 million, is still sitting in the withdrawal address, unmoved. And Liquid is still paused. L-BTC holders cannot convert their tokens back to bitcoin even as we speak.

The Facts: A Weekend That Emptied A "Federation Vault"

Rewind to Sunday, September 6. A customer sends 4,000 L-BTC – roughly $320 million, about 95% of everything Liquid’s federation wallet held – through SideSwap’s peg-out service. It never arrives. A flaw in how Liquid nodes cache range proof verifications let the attackers mint unbacked L-BTC and swap it for reserve bitcoin. One federation partner’s peg-out authorization key, used to unlock nearly the entire reserve.

Blockstream patched the bridge nodes within ten hours and shipped Elements v23.3.4 on Wednesday. On Monday, three thousand four hundred Bitcoin – around $265 million, 85% of the haul – came back to the federation address. The other 598.5 BTC stayed where the hackers left it. No agreement. No contracts. Nothing but a change address holding $47 million of other people’s money.

Then the invoice arrived – written into a Bitcoin transaction, because of course it was. The exploiters wrote that Blockstream allocated "only $1.5M (maybe even 0) to secure $5B assets," calling it "a flagrant neglect of security." Their terms: a 10% bounty "using your own money as bug bounty." As we told you two days ago, the threat behind the invoice was simple – pay up, or they "cause all your holders a 15% loss."

"Bitcoin Doesn’t Haircut Users" — Says the Company That Just Haircut Its Users

Now comes the part that should make every Liquid holder furious.

Blockstream says its participation in the talks "should not be mistaken for acceptance of the actions taken nor of the terms being demanded." Fair enough – you don’t negotiate with extortionists. Then it refuses to pay so its developers "should not be subject to paying a ransom that far exceeds their economic participation." Also defensible.

Then this: "Bitcoin is hard money and can’t be minted without costs. Bitcoin doesn’t haircut users to pay a ransom."

Bitcoin doesn’t haircut users. But 598.5 BTC of real, mainnet bitcoin – the actual reserve backing every L-BTC token in circulation – is in a stranger’s wallet and isn’t coming back yet. The peg is paused. You can’t cash out. The shortfall lands exactly where it always lands when custody fails: on the users, who did nothing wrong except trust the wrapper.

Blockstream instead promises "every lawful avenue" – law enforcement, exchanges, forensic specialists. "Transactions do not disappear, and neither does the evidence they leave behind," it warned, closing with "Return the bitcoin."

Cool. Tell that to the counterparty who answered a ransom note with a lecture and a shrug.

Charles Guillemet, CTO of Ledger, already said what nobody at Blockstream will say out loud: if the ~600 bitcoin still held is a reward negotiated through encrypted messages onchain, the arrangement "looked more like extortion" than responsible disclosure. Extortion. On a sidechain that was marketed as Bitcoin’s "institutional-grade" settlement layer.

The Lesson They Still Won’t Admit

Here’s what this whole saga actually is: a $320 million live-fire exercise in custody risk. The most respected names in Bitcoin infrastructure ran a sidechain. One partner’s peg-out key. One unpatched validation cache. And 95% of everything in the vault walked out the door in a weekend – returned only after a public shaming on the very blockchain it was built on.

Not your keys, not your coins. And in Liquid’s case: not your keys, not your coins, and not even the coins you THOUGHT were backing your tokens.

The federation held the stack. The federation got drained. The federation is now negotiating with its own hostage-takers in public, on-chain, while your L-BTC stays frozen. "Institutional-grade" was always just "someone else’s private keys."

Bitcoin doesn’t need a federation to hold your coins, and it never did. The only sidechain where you control the keys is the one you never leave: mainnet self-custody. Use coupon LOVEISBITCOIN at Bull Bitcoin and keep your stack where no white hat, no black hat, and no federation hat can touch it.

So here’s the question for the comment section: when the "trusted" sidechain loses 95% of its vault in one weekend and the best the custodians can offer the people holding the loss is a moral lecture – why would anyone with real bitcoin ever surrender their keys to a federation again?

Coupon: LOVEISBITCOIN — https://loveisbitcoin.com/bull

Previous

BLOCKSTREAM CALLS THE LIQUID RANSOM “THEFT” — BUT $47 MILLION OF USER BITCOIN IS STILL IN THE HACKER’S WALLET

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal