Wednesday, September 16, 2026

Creating liberating content

CoinEx quits after 9...

Crypto exchange CoinEx is shutting down after nine years, citing shrinking revenue and...

Bitcoin, BTC-Related Stocks Tumble...

Bitcoin’s price tumbled — along with crypto-related stocks — following the blockage of...

Bitcoin Core v32 RC1:...

Bitcoin Core v32.0rc1 has turned the Sept. 14–Oct. 10 window into a concentrated...

AI Could Be Bitcoin’s...

Artificial intelligence may turn out to be an unexpected driver of...

Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand

Blockstream is refusing to pay the Liquid attacker nearly 600 Bitcoin (roughly $50 million), escalating a dispute over how the crypto industry should reward partial restitution.

The standoff follows an unusual recovery from the Sept. 6 exploit, when a vulnerability allowed the attacker to create about 4,000 unbacked L-BTC and withdraw roughly 3,996 real BTC through SideSwap.

The attacker returned 3,400 BTC after Blockstream patched affected nodes, then demanded a 10% bounty paid from Blockstream’s own funds and warned that holders could otherwise bear a roughly 15% shortfall.

Table compiles on-chain messages attributed to the Liquid hackers and Blockstream, including PGP-signed exchanges and transactions connected to the return of 3,400 BTC. Source: Galaxy Research

On Sept. 11, Blockstream rejected the demand and said it would pursue the remaining funds through law enforcement, exchanges, service providers, and forensic specialists if they are not voluntarily returned.

The decision has opened a broader argument over whether refusing to compensate an attacker who returned about 85% of the haul strengthens deterrence or gives the next hacker less reason to return anything.

Blockstream’s rare recovery turns into a fight over incentives

The return of 3,400 BTC shifted the fight from recovering stolen funds to defining what cooperation after an exploit is worth.

Lorenzo Romagnoli, co-founder of USDT0, said Blockstream had already received an outcome that most hacked crypto protocols could only hope for. He argued that an attacker linked to North Korea or another committed criminal group would have little incentive to voluntarily send back hundreds of millions of dollars.

Romagnoli said:

“Blockstream is already in the 1% of the 1% of luckiest hacked protocols on the planet.”

He said Blockstream retains every right to identify and prosecute the attacker, but warned that refusing a substantial bounty could change future hackers’ calculations. A grey-hat attacker weighing whether to return stolen funds may see little upside in cooperation if restitution brings the same pursuit as keeping the entire haul.

Read More:  Binance pre-IPO contract pushes Anthropic to a $2.1 trillion implied valuation

That argument collides with Blockstream’s concern that paying would create a different incentive: allowing an attacker to exploit open-source infrastructure, seize user assets and then establish the price for returning them.

Blockstream said it would not establish a precedent in which developers of open-source software could be forced to pay a demand that “far exceeds their economic participation.” It also rejected the attacker’s white-hat characterization and urged the party to “return the Bitcoin.”

Related Reading

Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain

Samson Mow, a former Blockstream chief strategy officer and chief executive of Bitcoin company Jan3, also challenged the economics behind the attacker’s demand.