Industry News

Blockstream Refuses Ransom Demand After $46 Million Bitcoin Theft on Liquid Network

Bitcoin Magazine · 12 Sept 2026
Key Takeaway Businesses relying on blockchain or fintech platforms should ensure vendors have independent security audits and incident response plans, since even well-funded infrastructure can contain critical bugs that lead to large financial losses.

Blockstream, a bitcoin infrastructure company, has confirmed that attackers exploited an inflation bug in its Liquid sidechain to create thousands of bitcoin-backed tokens that did not previously exist, then cashed them out for real bitcoin. The breach saw around $320 million withdrawn from the network's federation wallet, though most funds were later returned after negotiation.

The attackers, who describe themselves as white hat hackers, have kept nearly 600 bitcoins (worth over $46 million) and are demanding the company let them retain a percentage of the stolen funds as a reward. Blockstream has firmly rejected this, stating publicly that withholding stolen assets and demanding payment is theft, not responsible disclosure. The company says it will now work with law enforcement, exchanges, and forensic specialists to trace the funds and identify those responsible.

The incident highlights how a single software flaw in a blockchain's core logic can allow attackers to fabricate value from nothing and extract it as real currency. It also shows how attackers can use blockchain messaging itself to communicate demands directly to a victim organisation.

Summarised by CISO AI from Bitcoin Magazine. We link back to every original so you can read it yourself.