Blockstream Hackers Demand 10% Bounty, Threatening Bigger Losses for Liquid Holders

Blockstream hackers
Table of Contents

TL;DR:

  • Attackers drained nearly 4,000 BTC from the Liquid network on September 6, 2026, and returned 3,400 BTC on September 8, 2026.
  • The group holds 598.5 BTC in its possession as of September 9, 2026, and demands the payment of a 10% bounty using the company’s corporate funds.
  • The warning transmitted via Bitcoin transactions indicates that a refusal would result in a 15% loss for Liquid users.

The conflict between infrastructure firm Blockstream and the hackers escalated following a demand for a 10% bounty and warnings of financial losses for users of the Liquid sidechain.

The incident began this past Sunday, September 6, when the group extracted nearly 4,000 BTC from Liquid’s reserves. Shortly after the movement of funds, the perpetrators posted messages on the blockchain framing themselves as white-hat researchers.

Both parties established contact via direct transactions and encrypted messaging. During the course of Tuesday, September 8, the Liquid federated wallet received back 3,400 BTC, while the attackers retained 598.5 BTC.

This remainder sits at the core of the current dispute. Through Bitcoin’s OP_RETURN function, the attackers relayed direct instructions to company leadership.

The message demanded that the firm fund the incentive with its own capital rather than deducting it from user balances. According to market reporting, the hackers asserted that rejecting their proposal could lead to a 15% deduction from depositors’ funds.

Additionally, the group questioned the tech firm’s cybersecurity budget allocations. According to the text embedded in the blockchain, the hackers claimed the company allocated $1.5 million or less to protect its systems.

Blockstream hackers

On-Chain Negotiations and Key Disclosure Risk

The OP_RETURN tool allows small fragments of data to be attached within standard Bitcoin transactions. This technical mechanism served as an open communication channel during negotiations over the last three days.

The attackers signaled their intent to release the private cryptographic key needed to decrypt conversations held with the technical team. If this step occurs, detailed communication records and the specific vulnerabilities exploited within the federation could be exposed to the developer community.

The Liquid network operates as a federated sidechain utilizing a multisig custody scheme to issue and back Bitcoin-pegged assets. A compromise in the control of these reserves puts operational trust at risk among the institutional traders and custodians that form the federation.

The retention of nearly 600 BTC altered how the incident is viewed. Analysts note that pairing coerced bounties with warnings of financial harm moves the maneuver far outside standard responsible disclosure practices.

Infrastructure firms often rely on bug bounty programs to remediate critical security flaws. However, industry analysts highlight that executing transfers under duress could set problematic precedents for Layer 2 protocols.

The immediate outcome hinges on the formal response issued by Blockstream leadership in the coming hours regarding the withheld 598.5 BTC. The industry remains watchful for an official update on the integrity of Liquid’s reserves and the potential leak of encrypted logs.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews