They still hold 598.5 Bitcoin — roughly $48 million — and on Wednesday the anonymous group that drained Liquid’s vault sent Blockstream their invoice: pay a 10% bounty "using your own money," or they will "cause all your holders a 15% loss."
Read that again. The people who stole $320 million are now demanding a ransom, on the record, in public. And the "victims" are negotiating.
This is not a Netflix thriller. This is the Liquid Network — Blockstream’s "institutional-grade" Bitcoin sidechain — and it is the most important lesson about self-custody you will see all year.
The Facts: A Ransom Note Written On The Bitcoin Blockchain
Rewind to Sunday, September 6. A customer sent 4,000 L-BTC — about $320 million, roughly 95% of everything held in Liquid’s federation wallet — through SideSwap’s peg-out service, the authorized bridge from Liquid back to Bitcoin mainnet. It never arrived. A stranger walked out with the vault.
Instead of vanishing, the actors left a message attached to a Bitcoin transaction: they’re "whitehats." They demanded Blockstream patch the flaw before any money returned. Blockstream signed its own transaction message back: bridge nodes patched, funds "safe to return."
On Monday, in block 965,950, three thousand four hundred Bitcoin — around $269 million, 85% of the haul — came home, as we told you yesterday. The other 598.5 BTC stayed in their address. No bounty agreement. No contract. No police report that matters, because there’s nobody to arrest and no jurisdiction that cares.
Then came Wednesday’s demand, delivered the only way that mattered: written on the Bitcoin blockchain itself via OP_RETURN. Blockstream, the group said, allocated $1.5 million — "maybe even 0" — to security: "a flagrant neglect of security and a sign of complete mismanagement." (Their words, and you should treat claims from the party holding $48 million hostage accordingly.)
The terms: "You SHALL pay 10% using your own money as bug bounty." Refuse, and they’ll "cause all your holders a 15% loss" — the 598.5 BTC gets burned. And if anyone gets cute, they’ll publish the private keys to the whole negotiation channel, encrypting nothing, hiding nothing.
Meanwhile, Liquid’s peg is halted. The network is frozen. Every exchange and every user holding L-BTC is stuck waiting for two parties to finish a hostage negotiation in full public view. It didn’t have to be this way.
Why This Is Your Problem
Let’s strip the theater away.
Liquid was sold as Bitcoin’s institutional fast lane: federation signers, audited code, vetted members, "don’t trust, verify." Eleven of fifteen hand-picked corporate functionaries had to sign every peg-out. Extra authorization keys stacked on top. That was the sales pitch exchanges bought and users were told to swallow.
And the result? A stranger walked off with the vault, gave 85% back as a favor, and is now holding the rest for a 10% cut of someone else’s money.
Now look at the two parties involved. The "white hats" hold $48 million of other people’s Bitcoin hostage and call it ethics. Blockstream called the funds "safe to return" — and left a $48 million hole open with no secured terms, no escrow, no recourse. The exchanges that parked customer money in Liquid are frozen solid. The users who were told "don’t trust, verify" are doing the verifying with their savings on ice.
Neither side is fighting for you. The white hats want a bounty. Blockstream wants its reputation back. You want your coins unfrozen — and nobody has promised you that. The only entity in this entire saga that never lied, never froze, never demanded a ransom? The Bitcoin network itself. Every message, every promise, every threat is written on it in permanent ink.
The Love Is Bitcoin Takeaway
Here’s the mic-drop: Liquid didn’t get hacked. Bitcoin didn’t get hacked. YOU got sidelined.
A sidechain run by a federation of hand-picked signers is not Bitcoin. It’s a company town with extra steps — and a company town can freeze, can negotiate, and can hand $48 million of your money to anonymous strangers who call themselves the good guys.
This is why self-custody matters. Because the moment your coins sit behind someone else’s multisig, someone else’s federation, someone else’s bug bounty dispute — they are not your coins anymore. They’re collateral in somebody else’s war.
So if you’re going to buy Bitcoin, buy the real thing and hold the keys yourself. Bull Bitcoin lets you do exactly that — no sidechain, no federation, no "trust us, we audited it." Stack sats you actually own, with coupon LOVEISBITCOIN, and cut out every middleman that could ever freeze, negotiate with, or ransom your coins.
Because the next time someone tells you their sidechain is "just as safe as Bitcoin," remember the 598.5 Bitcoin sitting in a whitehat’s wallet, waiting for a ransom that was never yours to pay.
If "whitehats" can hold $48 million of other people’s money and still be called the good guys — what exactly do you think the actual bad guys are doing with the coins on the exchange you still haven’t logged out of?
This article is for education only and is not financial advice.