Blockstream has refused a $50 million bounty demand from the Liquid attacker, recovering most of the stolen Bitcoin but leaving nearly 600 BTC missing and the network's peg suspended.
Blockstream has refused to pay a nearly $50 million bounty to the attacker behind the Liquid network exploit, even after most of the stolen Bitcoin was returned. The company's decision leaves a gap of 598.5 BTC in the Liquid reserve and has sparked debate over how protocols should respond when only part of the stolen funds are recovered.
Standoff over returned funds
The dispute began with a September exploit that let an attacker mint about 4,000 unbacked L-BTC and withdraw roughly 3,996 real BTC from the Liquid network using SideSwap. The incident occurred on September 6, 2026, due to a flaw in the open-source Elements software's range-proof cache validation, which allowed unauthorized L-BTC creation. Blockstream patched the bug in its bridge nodes on September 7. The attacker then returned 3,400 BTC but demanded a 10% bounty-nearly 600 BTC-from Blockstream's own funds, warning that Liquid holders would otherwise face a 15% reserve shortfall. Blockstream refused, saying it would not pay bounties that far exceed the economic role of open-source developers and would instead work with law enforcement and forensic teams to recover the rest.
Blockstream reported that the attacker returned 3,400 BTC, leaving approximately 598.5 BTC outstanding-about 15% of the total stolen.
Liquid Network Incident Report
Security and economic fallout
With the bounty off the table, the missing 598.5 BTC remains a problem for the network. SideSwap, which handled the peg-out withdrawals, said the attacker rehearsed the exploit with dozens of test transactions and used Tornado Cash to hide the funding trail. According to SideSwap, the peg-out order "went through SideSwap's peg-out service on a customer order," and its PAK was not compromised; the LBTC came from the Elements bug, not a SideSwap failure. The wallet holding the missing BTC is now under close watch, making it hard for the attacker to move or cash out the funds without revealing their identity. As of September 10, SideSwap reported 4,205 L-BTC in circulation against a reserve of 3,597 BTC, leaving Liquid at about 85% reserve coverage even after the partial return.
Industry reaction and precedent
Opinions are divided on Blockstream's response. Some, like USDT0 co-founder Lorenzo Romagnoli, point out that Blockstream is unusually lucky to have recovered 85% of the stolen Bitcoin, since attackers linked to more organized groups rarely return funds. Others warn that refusing a large bounty could make future attackers less likely to cooperate, risking total losses in similar cases. Blockstream maintains that the attacker's actions do not count as white-hat behavior and insists that all user assets must be returned. The company has not said how it will address the reserve gap if the missing BTC is not recovered.
Liquid network status
Liquid has resumed block production after the patch, but peg-in, peg-out, and L-BTC transaction services are still suspended during recovery, according to Liquid's public incident update. SideSwap markets have reopened, but the federation is still reviewing security and preparing a new architecture. Blockstream CEO Adam Back has said the L-BTC-to-BTC peg will eventually be restored to full coverage and urged holders not to sell at a discount. Until the missing BTC is recovered or the reserve is topped up from other sources, Liquid's one-to-one redemption promise remains on hold. The ongoing reserve gap continues to put pressure on the network's credibility and user trust.
The Liquid Network operates as a Bitcoin sidechain, using a federation of functionary nodes to manage peg-in and peg-out processes. Its security model relies on multi-signature custody and periodic audits, but the recent exploit exposed vulnerabilities in the underlying Elements software, prompting a comprehensive review of protocol architecture and operational controls.
CoinDesk (source)
Previous investigations have shown that persistent security gaps in crypto infrastructure can leave user funds at risk even after initial exploits are patched, underscoring the need for strong incident response and transparent recovery efforts (source).
On September 6, the Liquid network exploit led to the unauthorized creation of about 4,000 L-BTC and the withdrawal of roughly 3,996 BTC, according to Blockstream. After the attacker returned 3,400 BTC, reserve coverage improved to about 85%, but the remaining 598.5 BTC shortfall still affects the network's ability to honor peg-outs. As of September 10, SideSwap reported 4,205 L-BTC in circulation and 3,597 BTC in reserve, with peg-in and peg-out services still suspended while security is overhauled.
When a protocol's reserve drops below full backing, as with Liquid's current 85% coverage, the risk to users rises. Holders may not be able to redeem tokens for the underlying asset at par, and discounts can appear on secondary markets as confidence fades. Refusing a bounty in exchange for partial restitution sets a precedent that may discourage some attackers from returning funds, but it also signals that protocols will not negotiate with exploiters. The balance between deterrence and practical recovery remains a key challenge for decentralized networks facing advanced security threats.