Crypto news report · source clearly identified

Blockstream Declines Payment to Hackers After Liquid Sidechain Theft

Blockstream refused to pay a 10% bounty to attackers who stole roughly 4,000 BTC from its Liquid sidechain, leaving about 598 BTC still unrecovered.

Blockstream announced it will not provide a bounty to the individuals who exploited a software flaw in its Liquid sidechain on September 6, resulting in the theft of approximately 4,000 Bitcoin (BTC). The company’s decision breaks with a recent practice of offering a percentage of recovered funds to self‑identified white‑hat hackers.

Incident overview

The vulnerability allowed attackers to create Liquid tokens without corresponding BTC backing and to convert those tokens out of the network. Federation signing keys were not compromised, so the draining transaction cleared as a normal transfer. After Blockstream patched the flaw, the attackers returned about 3,400 BTC and retained roughly 598.5 BTC, valued at around $46 million at current prices.

Requested bounty and industry precedent

Following the partial return, the attackers asked for a retroactive bug bounty equivalent to 10% of the stolen amount. This request mirrors a model popularized after the 2022 Nomad bridge loss, where the bridge’s operators offered a 10% reward to hackers who would return the remaining funds.

Blockstream’s response

In a public statement, Blockstream argued that open‑source developers should not fund payouts exceeding their own stake in a network. It characterized the unauthorized taking of assets and the withholding of their return as theft, not responsible disclosure, and therefore not a white‑hat activity.

Broader context

Blockstream is not alone in rejecting such payouts. In 2024, Kraken labeled a similar demand by security researchers as extortion after they took $3 million and set a price for its return. The unresolved 598 BTC from the Liquid incident remains unrecovered, and Blockstream has not disclosed how the loss will be absorbed.

Next steps

Recovery efforts now depend on law‑enforcement actions, exchange cooperation, and blockchain forensics to identify the perpetrators. The outcome of Blockstream’s refusal may influence future demands from attackers in similar incidents.

Source & attribution

News Source

Publisher
BeInCrypto
Original date
September 11, 2026, 12:09 PM
Original headline
Blockstream Refuses the 10% Cut White Hat Hackers Have Learned to Expect
View original report ↗