Blockstream is refusing to pay the Liquid attacker nearly 600 Bitcoin—worth roughly $50 million—following a dispute over compensation for partial restitution of funds stolen in a September 6 exploit.
The incident began when a vulnerability allowed an attacker to create approximately 4,000 unbacked L-BTC and withdraw roughly 3,996 real BTC through SideSwap. After Blockstream patched affected nodes, the attacker voluntarily returned 3,400 BTC but demanded a 10% bounty paid from Blockstream's own funds. The attacker warned that L-BTC holders could otherwise face a roughly 15% shortfall.
On September 11, Blockstream rejected the demand and said it would pursue the remaining funds through law enforcement, exchanges, service providers, and forensic specialists if not voluntarily returned.
Competing Views on Recovery Incentives
The standoff has sparked debate over whether refusing compensation strengthens deterrence or discourages future attackers from returning stolen assets. Lorenzo Romagnoli, co-founder of USDT0, argued that Blockstream had already achieved an unusually favorable outcome—most hacked protocols recover far less than 85% of stolen funds. He cautioned that refusing a substantial bounty could signal to future attackers that cooperation offers no advantage over keeping the entire haul.
Blockstream countered that paying would establish a dangerous precedent, allowing attackers to exploit open-source infrastructure and then dictate ransom terms. The company stated it would not compensate demands that "far exceed their economic participation" in the network.
Samson Mow, former Blockstream chief strategy officer, also challenged the bounty calculation. The attacker had cited roughly $5 billion in assets on Liquid as justification for the demand, but Mow noted that figure combines L-BTC, Tether, and real-world assets belonging to different issuers and holders, making it an inappropriate basis for determining bounty size.
Questions About Attack Circumstances
SideSwap revealed that the attacker spent hours rehearsing the transaction pattern before executing the exploit, with 70 similar transactions preceding the successful mint. Additionally, the wallet used to initiate the attack had received funding traced through a cross-chain bridge to Tornado Cash. SideSwap characterized the event as a "deliberate and prepared attack" and pledged support for Blockstream's recovery efforts.
Bitcoin researcher Alex Waltz suggested the attacker may have limited practical ability to spend the remaining 598.5 BTC, as the closely monitored wallet would likely generate investigative leads if the coins moved through exchanges or custodians. Waltz proposed the attacker might retain the funds as economic pressure on Liquid rather than expecting to liquidate them.
Ongoing Operational Impact
SideSwap reported on September 10 that 4,205 L-BTC remained in circulation while the federation reserve held 3,597 BTC, resulting in approximately 85% reserve coverage. Liquid has resumed producing blocks and SideSwap markets have reopened, but peg-ins and peg-outs remain disabled during the federation's security review.
Blockstream Chief Executive Adam Back said the L-BTC-to-BTC peg would ultimately achieve one-for-one coverage and urged holders not to sell at a discount. Blockstream has not disclosed how it will finance the roughly 600-BTC gap if the attacker refuses to return the funds, or when full redemptions will resume. SideSwap has said it will keep its peg service offline until the federation introduces new security architecture before reopening.


