What exactly happened?
On September 6, a vulnerability was exploited in the Liquid Network, which is operated by Blockstream. Liquid is a so-called sidechain on top of Bitcoin, where L-BTC (Liquid Bitcoin) is a token that is supposed to be backed by real bitcoins at a 1:1 ratio.
According to CryptoSlate's account, the bug allowed the attacker to create roughly 4,000 unbacked L-BTC and, via the SideSwap service, extract approximately 3,996 real BTC. In other words, the attacker minted tokens without backing and swapped them for real bitcoins.
After Blockstream deployed a fix to the affected nodes, part of the funds was returned.
How much money was returned and how much is missing?
According to The Defiant, Liquid reported on September 8 that the attacker had returned 3,400 BTC and that at that moment roughly 598.5 BTC remained unpaid.
| Item | Amount of BTC | Source |
|---|---|---|
| Estimate of originally extracted funds | ~3,996 BTC | CryptoSlate |
| Returned by the attacker | 3,400 BTC | The Defiant, Incrypted |
| Still outstanding | ~598.5 BTC | The Defiant, Decrypt |
The value of the remaining amount differs slightly across sources depending on the exchange rate at the time of writing: Decrypt cites roughly 47 million dollars, while CryptoSlate mentions around 50 million dollars. This is an estimate that changes along with the price of Bitcoin.
What is the attacker demanding?
According to CryptoSlate, after returning 3,400 BTC the attacker requested a 10% "bounty" that Blockstream would have to pay out of its own funds. The attacker also reportedly warned that otherwise holders could face a loss of roughly 15%.
So this is a dispute over whether a reward should be paid for the partial return of stolen funds, and who should foot the bill.
How did Blockstream respond?
In a statement on X on September 11, Blockstream said it would not pay the ransom. According to Incrypted and Decrypt, the company described the conduct as theft, not as a responsible disclosure of a vulnerability.
A translation of the statement's meaning (Incrypted): acquiring assets without permission and refusing to return them is a crime, not responsible disclosure, and is not white hat activity. The term "white hat" refers to a security researcher who reports a bug and returns the funds, typically in exchange for a previously agreed reward.
Decrypt adds that if the funds are not returned, Blockstream intends to turn to law enforcement.
Why does this matter?
The dispute illustrates a broader debate in crypto: how the industry should treat attackers who return part of the funds and claim a "reward" for the rest. Blockstream is taking a hard line and framing the whole affair as theft, not as a bug bounty negotiation.
What remains uncertain?
The available sources do not yet make clear whether and how criminal complaints have been filed, whether the attacker has been identified, or whether further funds will be returned. It is also not confirmed what exact loss might ultimately fall on L-BTC holders. These are the points worth following in cases like this.

