1

Blockstream Says No to a 600 BTC Bounty After Liquid Hack

The short version (because you probably just skim headlines anyway)

Someone exploited Liquid on Sept. 6 and managed to mint a pile of unbacked L-BTC, then pulled out roughly 3,996 real BTC. After Blockstream fixed vulnerable nodes, the attacker sent back about 3,400 BTC — which is generous-ish — and then asked for a 10% finder’s fee (about 600 BTC) from Blockstream. Blockstream replied with a flat “no” and said it will chase the rest through law enforcement, exchanges and forensic sleuths instead of cutting a giant bounty check.

Why this is a spicy debate

There are two messy incentives staring each other down. One side says: if you pay a big bounty when an attacker returns most of the loot, you create a payday for future exploiters — basically turning hacks into negotiated sales. The other side says: if you refuse any payment, you remove the reason a so-called gray-hat might hand back anything, so future attackers might just keep everything and disappear.

Complicating the moral math: the attack didn’t look accidental. The service that processed peg-outs says the attacker rehearsed the move many times and used a wallet funded through a cross-chain bridge that traced back to a privacy tool, which makes the “white-hat” story less convincing. That service and Blockstream have been cooperating to trace and recover coins.

Forensics folks have pointed out that the wallet still holding the roughly 600 BTC is under heavy surveillance. Any attempt to funnel those coins through normal exchanges or custodians could leave breadcrumbs for investigators. That might explain why the attacker would either hope for a bounty or keep a hard-to-spend slice of the haul to keep pressure on Liquid.

On the operational side, Liquid markets have partially restarted and blocks are being produced again, but peg-ins and peg-outs remain paused while the federation reviews security. After the partial return, reserve coverage is only around 85%, so the promise to convert L-BTC back to Bitcoin is in limbo until that gap is closed — either by the attacker returning the remainder or someone else filling it.

Blockstream’s leadership insists the peg will be honored one-for-one eventually and doesn’t want to set a precedent where open-source devs are effectively forced to pay huge ransoms that exceed their involvement. Others counter that this outcome — getting most money back without a payout — is already rarer than a unicorn and might not be replicable for less fortunate projects.

So, we’re left with the classic crypto soap opera: recoveries, reputations, legal threats, and a stubborn pile of BTC being watched like a priceless cookie jar. Will Blockstream win by standing firm? Will the attacker try risky moves and get caught? Or will the leftover 600 BTC become a long-term headache? Popcorn-ready answers may arrive slowly.