Industry News

Blockstream's Liquid Network Hack: Was a Warning Ignored?

Bitcoin · 11 Sept 2026
Key Takeaway Businesses relying on third-party financial infrastructure should ask vendors how they handle vulnerability disclosures and whether reported bugs are patched promptly, since delayed responses can turn known issues into costly breaches.

The Bitcoin Red Team, a volunteer group that audits vulnerabilities in bitcoin-related projects, has suggested it previously disclosed the flaw later used to move close to 4,000 BTC (worth roughly $319 million) from Blockstream's Liquid federation wallets. The group's co-lead, known as Calle, publicly disputed Blockstream CEO Adam Back's explanation that the bug stemmed from an incorrect fix to an AI-found, non-critical issue, saying Blockstream had only selectively acknowledged prior patches.

Former Blockstream CSO Samson Mow pushed back, denying that any warning emails were ignored and criticising the insinuation. The Bitcoin Red Team says it will hold off sharing its full account of the disclosure timeline until Blockstream publishes its own postmortem of the incident.

Liquid has since restarted block production and transactions, though peg-outs remain disabled as a precautionary measure with no set timeline for resumption. The white-hat hacker involved still controls the remaining stolen funds, and restoring the 1:1 peg between BTC and L-BTC will require a third party to deposit replacement assets.

Summarised by CISO AI from Bitcoin. We link back to every original so you can read it yourself.