Industry News

Blockstream Refuses $50 Million Bounty Demand After Liquid Network Hack

CryptoSlate · 12 Sept 2026
Key Takeaway Businesses relying on open-source or blockchain infrastructure should have an incident response plan that includes legal and law enforcement engagement, rather than relying on negotiation with attackers.

Blockstream has refused to pay nearly 600 Bitcoin (about $50 million) to the attacker behind a September 6 exploit of its Liquid network. The attacker used a vulnerability to create roughly 4,000 unbacked L-BTC tokens and withdrew about 3,996 real Bitcoin through the SideSwap platform.

After Blockstream patched the affected nodes, the attacker returned 3,400 BTC but demanded a 10% bounty paid from Blockstream's own funds, warning that Liquid holders could otherwise absorb a roughly 15% shortfall. On September 11, Blockstream rejected this demand, saying it would pursue the remaining funds through law enforcement, exchanges, and forensic specialists if they are not voluntarily returned.

The case has sparked debate in the crypto industry about incentives following a breach. Some argue that refusing to reward an attacker who returned most of the stolen funds could discourage future cooperation from hackers, while Blockstream maintains that paying would set a dangerous precedent, effectively letting attackers set their own price for returning stolen assets from open-source infrastructure.

Summarised by CISO AI from CryptoSlate. We link back to every original so you can read it yourself.