Liquid Network's "White Hat" Hackers Keep $47 Million, Demand a Bigger Cut From Blockstream

The saga around the Liquid Network hack took a sharper turn this week, as the hackers holding the last piece of stolen Bitcoin sent Blockstream an on-chain message accusing the company of negligence and demanding a bigger payout.
HOW WE GOT HERE
Liquid is a federated Bitcoin sidechain built by Blockstream, where a group of exchanges and businesses lock real Bitcoin into a shared wallet and issue a one-for-one token, L-BTC, against it. On September 6, attackers exploited a bug and pulled roughly 4,000 BTC out of that federation wallet. Blockstream said hackers who claim to be white hats took about 4,000 bitcoin from the federation wallet, putting the value at about $320 million at the time. The withdrawal was devastating to the sidechain's reserves: it took roughly 95% of Liquid's reported bitcoin reserves, which stood at about 4,200 bitcoin beforehand.
Blockstream was quick to clarify that its signing keys were never touched. The bug instead sat in the software that validates the sidechain's tokens: no federation multisig keys were compromised, the flaw sat upstream, in the software that validates transactions before they reach the 11-of-15 signing federation. A range-proof bug in Elements, the open-source code Liquid runs on, let the attackers mint L-BTC that was never actually backed and redeem it for real Bitcoin through SideSwap's Peg-out Authorization Key, one of the keys that release funds from the sidechain.
THE NEGOTIATION PLAYED OUT ON CHAIN
What happened next was unusual even by crypto hack standards. The purported white-hat hacker communicated with Blockstream through Bitcoin OP_RETURN messages and PGP-encrypted text. The hackers told Blockstream to fix the bug and patch every node before they would send anything back, and Blockstream complied: Adam Back-led Blockstream subsequently sent a PGP-signed onchain message saying, "Bridge nodes are patched, safe to return the funds," a signature that verifies against the security key published on Blockstream's website.
The hackers largely kept their word. The hackers returned around 3,400 BTC after Blockstream patched the vulnerability, but kept roughly 598 BTC, worth roughly $47 million, as a self-declared bounty.
THE STANDOFF OVER THE LAST 598 BTC
That remaining sum is where things have gotten ugly. Ledger's chief technology officer publicly questioned the legitimacy of the arrangement: Charles Guillemet said 3,400 BTC had been returned by the purported white-hat hackers, leaving roughly 600 BTC still under their control, and questioned whether the remaining funds could reasonably be described as a legitimate bug bounty.
The hackers' latest message did not help their case. In an on-chain note shared publicly, the group accused Blockstream of underfunding security and threatened losses for L-BTC holders if the company did not pay up, telling Blockstream it would "pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss," and adding that Blockstream remains "delusional, greedy and arrogant to this very day." The group said it would publish the private key to its encrypted conversation with Blockstream afterward.
Whether this was ever a genuine white hat recovery or an extortion attempt dressed up as one is now the open dispute. No bug bounty program set a $47 million price on this class of flaw, and the actors named themselves white hats only after they already held the coins. What is unresolved is simple: whether Blockstream pays the 10 percent the hackers are now demanding, or the remaining 598.5 BTC stays gone. Liquid remains paused while that standoff plays out.
This story comes from the Simply Bitcoin Live show. Watch the full episode.



