Advertisement

Blockstream Rejects Ransom Demand After Liquid Bitcoin Exploit

Liquid said on Sept. 8 that 3,400 BTC had been returned and about 598.5 BTC remained outstanding; transactions later resumed with peg-outs disabled.
Blockstream Rejects Ransom Demand After Liquid Bitcoin Exploit

Blockstream said on Sept. 11 that it will not pay a ransom for bitcoin taken in the Liquid Network exploit. Liquid reported on Sept. 8 that the actors had returned 3,400 BTC and that approximately 598.5 BTC remained outstanding at that time.

In a statement, Blockstream called the taking and continued withholding of the bitcoin theft rather than white-hat activity. It said that if the funds are not returned, it will work with law enforcement, exchanges, service providers and forensic specialists to trace the assets and identify those responsible.

For Liquid users, the recovery remains incomplete. The network resumed block production and transactions on Sept. 10, but peg-outs — the mechanism used to move bitcoin out of Liquid — remained disabled as a precaution while recovery work continued.

Most of the Bitcoin Was Returned

Liquid’s Sept. 8 incident report, which gave the network’s status as of 19:10 UTC that day, said the Sept. 6 exploit created about 4,000 L-BTC that was not backed by bitcoin in the network’s reserve. The actors then converted the unbacked L-BTC into BTC through Liquid’s standard peg-out process, releasing about 4,000 BTC.

The report said no private keys were compromised. Instead, the exploit targeted how nodes running the open-source Elements software cached range-proof verifications, causing the unbacked L-BTC to be accepted as valid before the peg-out was processed.

Liquid said the actors returned 3,400 BTC to the Liquid Federation peg wallet on Sept. 7. Its Sept. 8 accounting put the amount then outstanding at approximately 598.5 BTC, or 15% of the total. The actors had left a message on the Bitcoin blockchain identifying themselves as white-hat security researchers and asking to be contacted about the vulnerability.

Blockstream rejected that characterization. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure,” the company said. “It is not white-hat activity. It is theft.”

The company said its previous engagement was intended to recover user funds and should not be treated as acceptance of the actors’ actions or demands. It also argued that paying would set a precedent in which developers of open-source Bitcoin software could face ransom demands exceeding their economic participation.

Liquid announced on Sept. 9 that the emergency Elements v23.3.4 release was available and addressed the proof-verification cache vulnerability. As of Liquid’s latest operational update, transactions were running again, but peg-outs remained disabled pending the final stage of recovery.

Advertisement

Get an edge in Crypto with our free daily newsletter

Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri

90k+ Defiers informed every day. Unsubscribe anytime.