Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand

by

Blockstream is refusing to pay the Liquid attacker nearly 600 Bitcoin (roughly $50 million), escalating a dispute over how the crypto industry should reward partial restitution.

The standoff follows an unusual recovery from the Sept. 6 exploit, when a vulnerability allowed the attacker to create about 4,000 unbacked L-BTC and withdraw roughly 3,996 real BTC through SideSwap.

The attacker returned 3,400 BTC after Blockstream patched affected nodes, then demanded a 10% bounty paid from Blockstream’s own funds and warned that holders could otherwise bear a roughly 15% shortfall.

Blockstream and Liquid Network Hacker
Table compiles on-chain messages attributed to the Liquid hackers and Blockstream, including PGP-signed exchanges and transactions connected to the return of 3,400 BTC. Source: Galaxy Research

On Sept. 11, Blockstream rejected the demand and said it would pursue the remaining funds through law enforcement, exchanges, service providers, and forensic specialists if they are not voluntarily returned.

The decision has opened a broader argument over whether refusing to compensate an attacker who returned about 85% of the haul strengthens deterrence or gives the next hacker less reason to return anything.

Blockstream’s rare recovery turns into a fight over incentives

The return of 3,400 BTC shifted the fight from recovering stolen funds to defining what cooperation after an exploit is worth.

Lorenzo Romagnoli, co-founder of USDT0, said Blockstream had already received an outcome that most hacked crypto protocols could only hope for. He argued that an attacker linked to North Korea or another committed criminal group would have little incentive to voluntarily send back hundreds of millions of dollars.

Romagnoli said:

“Blockstream is already in the 1% of the 1% of luckiest hacked protocols on the planet.”

He said Blockstream retains every right to identify and prosecute the attacker, but warned that refusing a substantial bounty could change future hackers’ calculations. A grey-hat attacker weighing whether to return stolen funds may see little upside in cooperation if restitution brings the same pursuit as keeping the entire haul.

That argument collides with Blockstream’s concern that paying would create a different incentive: allowing an attacker to exploit open-source infrastructure, seize user assets and then establish the price for returning them.

Blockstream said it would not establish a precedent in which developers of open-source software could be forced to pay a demand that “far exceeds their economic participation.” It also rejected the attacker’s white-hat characterization and urged the party to “return the Bitcoin.”

Related Reading

Tokens created out of thin air may explain how $320 million in Bitcoin left the Liquid sidechain

Samson Mow, a former Blockstream chief strategy officer and chief executive of Bitcoin company Jan3, also challenged the economics behind the attacker’s demand.