Crypto

$320 Million Left Blockstream's Liquid Network. The Party Holding $46 Million Calls It a Bug Bounty.

Roughly 3,400 of 4,000 bitcoin were returned after a patch. Blockstream refuses to pay for the rest, and has said so in unusually direct language. On September 6, an exploit against Blockstream's Liquid Network, a Bitcoin sidechain, resulte…

$320 Million Left Blockstream's Liquid Network. The Party Holding $46 Million Calls It a Bug Bounty.
$320 Million Left Blockstream's Liquid Network. The Party Holding $46 Million Calls It a Bug Bounty.

Roughly 3,400 of 4,000 bitcoin were returned after a patch. Blockstream refuses to pay for the rest, and has said so in unusually direct language.

On September 6, an exploit against Blockstream's Liquid Network, a Bitcoin sidechain, resulted in the extraction of roughly 4,000 BTC, worth approximately $320 million at the time.

After Blockstream released patched bridge-node software, approximately 3,400 BTC was voluntarily returned. Approximately 598 BTC, worth roughly $46 million, remains with the attackers, who have not returned it.

The dispute is over what to call the remainder.

The party holding the remainder has described the sum as a bounty, framing the episode as white-hat security research. Blockstream's public position leaves no room for that reading: "Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft."

The distinction being contested is not semantic

Responsible disclosure in security research follows a recognized sequence: a researcher finds a vulnerability, reports it privately, gives the operator time to patch, and is compensated under a pre-existing bounty programme or through negotiation after the fact. The researcher does not take custody of the assets at risk.

Taking 4,000 bitcoin and returning 85% of it after a patch ships is a different sequence entirely. Whatever the intent, custody changed hands without authorization, and the withheld portion is retained against the operator's stated refusal to pay. That is the definitional line Blockstream is drawing, and it is a line the industry has generally recognized.

The commercial reason operators hold that line is straightforward. Paying a party that has already demonstrated both the capability and the willingness to take custody establishes a price for future attempts against every protocol.

An unverified allegation sits underneath all of it

A security research group identifying itself as Bitcoin Red Team has separately claimed it warned Blockstream of the underlying vulnerability before the exploit and that the warnings were not acted upon.

Blockstream has not addressed the claim and no independent party has confirmed it, and it comes from a group with its own stake in how this episode is remembered. It should not be treated as established. It should also not be dismissed, because if it is substantiated it converts the story from a security incident into an operational accountability question, and it is the specific allegation most likely to determine how this episode is remembered.

The network is not fully back

Liquid Network block production has resumed, though it is producing empty blocks. Transaction processing and peg-in and peg-out functions, the mechanisms by which bitcoin enters and leaves the sidechain, remain suspended.

That partial restoration is the operational fact that matters most to users. A network producing empty blocks is running but not usable, and assets on the sidechain cannot presently be moved back to the Bitcoin main chain.

The resolvable questions are whether peg functionality is restored and on what timeline, whether the withheld 598 BTC is returned or pursued, and whether the prior-warning allegation is substantiated or withdrawn.

More articles from FinancialMarkets.com