The standoff surrounding Blockstream’s Liquid sidechain escalated after the party claiming to be a white-hat hacker demanded a 10% bug bounty from Blockstream and accused the company of “flagrant neglect of security.” The hacker, who previously withdrew close to 4,000 BTC from Liquid’s Federation wallet, alleged that only $1.5 million—or possibly nothing—was allocated to secure $5 billion in assets, and warned that refusal to pay could cause a 15% loss for Liquid users.
According to updates from former Blockstream CSO Samson Mow and the @Liquid_BTC account, the incident began on September 6 when roughly 4,000 BTC—worth about $320 million at the time and representing around 95% of the wallet’s balance—was moved using SideSwap’s peg-out authorization key. Blockstream said the key was never stolen and attributed the vulnerability to a flaw in Elements, the open-source software underpinning Liquid, which allowed invalid L-BTC to be created and redeemed as if fully backed.
After an emergency patch, Elements v23.3.4, was deployed to harden cache keys used for range proofs, Blockstream signed an on-chain message stating that bridge nodes were patched. The actor returned 3,400 BTC, worth roughly $269.2 million, leaving approximately 598.5 BTC—about $46 million to $47 million—outstanding. “You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the hacker wrote.
Liquid resumed block production on Thursday initially without transactions, and a later update confirmed transactions had resumed while peg-in and peg-out operations remain switched off. Founder and CEO Adam Back reassured users that the L-BTC peg will be honored one-for-one and urged them not to panic sell OTC, but he did not say how the roughly 600 BTC shortfall would be covered or provide a timeline for restoring peg services. Mow separately cautioned the hackers that they may have left more clues than they realize, adding: “Some doors, once opened, can never be closed again.”