Blockstream Refuses Ransom Payment After $46M Bitcoin Theft From Liquid Network

October 6, 2026 27 views

Bitcoin infrastructure company Blockstream has rejected ransom demands following a significant security breach of its Liquid sidechain that resulted in the theft of approximately $320 million in bitcoin. The incident, which exploited an inflation bug in the network, raises fresh concerns about layer-2 security practices and the blockchain industry's vulnerability to sophisticated attacks.

The Breach and Ransom Demand

Attackers exploited a critical inflation vulnerability in Liquid's protocol to create over 4,000 unauthorized LBTC tokens, which they subsequently converted to on-chain bitcoin. While the hackers initially returned most of the stolen funds—approximately $274 million—they retained 598.5 BTC (valued at over $46 million) and demanded payment as a bug bounty.

Blockstream firmly rejected this characterization, stating in a public message that "taking assets without authorization and withholding their return is a crime, not responsible disclosure." The company emphasized it would not negotiate further and announced plans to work with law enforcement, exchanges, and forensic specialists to recover the remaining assets and identify those responsible.

The attackers communicated through messages embedded in Bitcoin blocks, initially framing their actions as "white-hat" security research. However, their subsequent demands—including a 10% ransom threat—undermined this claim. In their latest message, the hackers threatened to expose encrypted communications unless Blockstream paid the demanded sum.

Implications for Blockchain Security Professionals

This incident highlights the growing demand for security engineers and auditing specialists in the web3 space. The exploit of Liquid's inflation bug demonstrates the critical importance of thorough code reviews and comprehensive security testing before deploying layer-2 solutions.

For blockchain professionals, this breach underscores several key points: security roles remain mission-critical across all blockchain infrastructure projects, companies continue investing heavily in forensic capabilities and threat detection, and the industry needs clear protocols for responsible vulnerability disclosure.

The timing is particularly concerning given July's Coldcard wallet breach, which compromised over $140 million due to inadequate random number generation. These consecutive high-profile incidents suggest sustained demand for experienced security talent across infrastructure providers, wallet developers, and layer-2 platforms.

🏢 Companies mentioned in this article