Your signal. Your price.
Liquid Network attackers returned 3,400 of the 4,000 stolen Bitcoin but kept nearly 600 coins as a ransom. Adam Back confirmed the Liquid peg will remain fully covered one-to-one, while Blockstream refuses to negotiate with the hackers.
An attacker exploited Liquid's consensus engine to drain 4,000 BTC from its 11-of-15 multisig federation. The hacker returned 3,400 BTC but kept 600 BTC as an involuntary bounty, demanding a 10% voluntary payment for the rest.
Blockstream communicated with the Liquid hacker via PGP-encrypted onchain messages before the attacker threatened to publish negotiations in plain text. Blockstream plans to pursue every legal avenue to recover the remaining 600 stolen Bitcoin.
Security researcher Cali publicly claimed Blockstream could have avoided the Liquid exploit by answering red team emails. Keon criticizes this as clout-chasing influencer behavior, arguing that effective security work must be conducted quietly.
Summerwill highlights data showing Ethereum's Layer 2 ecosystem capitalization reached 30 percent of its Layer 1 value. In comparison, Bitcoin's L2 market share, including Liquid and Stacks, languished at roughly 1 percent of its Layer 1 value.
Ezra Regreira reports that Blockstream refused to pay a 10% ransom to hackers who exploited the Liquid Network federation wallet. The hackers initially withdrew 4,000 Bitcoin but returned 3,400 after Blockstream patched the affected bridge nodes.
Blockstream Liquid was hacked for 4,000 BTC after an attacker exploited an inflation vulnerability. The exploit resulted from a flawed code patch released on September 1, 2024, which attempted to fix an older 2018 range proof vulnerability.
Adam Back announced the Liquid network peg will remain one-for-one. Blockstream and its partners are plugging the remaining 600 BTC deficit after the hacker returned 3,400 BTC through encrypted OP_RETURN negotiations, keeping 15 percent as an unsolicited bounty.
The Liquid exploit exposed structural risks in federated sidechains, where members blindly run software updates without auditing the code. The attacker bypassed security controls by exiting through Sideswap, a federation member that lacked KYC or transaction velocity controls.