Blockstream exploit exposes federated custody vulnerabilities
- A code bug enabled an attacker to steal 4,000 Bitcoin from Blockstream's Liquid sidechain.
- Federated signers approved fake coins because all nodes ran identical unpatched software.
- The attacker returned 3,400 Bitcoin while extracting a $48 million ransom from Blockstream.
Federated multi-sig custody failed its biggest real-world test.
An attacker exploited a consensus code bug to drain 4,000 Bitcoin - worth roughly $320 million - from Blockstream's Liquid sidechain. The underlying Elements software used a caching shortcut for range proofs to save processing time, but failed to verify asset context. The attacker generated fake Liquid Bitcoin out of thin air and routed them through SideSwap to trigger a standard peg-out.
On Ungovernable Misfits, hosts q and a explained how eleven federation signers authorized the withdrawal without hesitation. Because every federation node ran the same unpatched software, every signer reached the exact same faulty validation result. Multi-signature security proved useless against homogenous software consensus. An open pull request fixing the caching logic had sat unmerged for weeks before the exploit occurred.
The aftermath played out across public blockchain transactions. Using encrypted OP_RETURN and PGP messages, the attacker claimed white-hat status and demanded a 15 percent ransom. Blockstream pushed back against the size of the fee, but negotiations abruptly ended when the hacker sent a sad-face emoji and walked away with 598.5 Bitcoin - worth roughly $48 million - while returning the remaining 3,400 BTC.
On Bitcoin And | Bitcoin & Economic News, analyst David Bennett pointed to a broader trend accelerating these breaches. AI-powered vulnerability tools now scan open-source repositories continuously, allowing bad actors to build weaponized exploits faster than human developers can deploy patches. In this case, an open pull request sitting unmerged for weeks gave attackers all the blueprint they needed.
Despite the lost funds, Blockstream CEO Adam Back announced that the Liquid network peg would remain one-for-one, with Blockstream and its partners backstopping the remaining 600 Bitcoin deficit. Yet the fix does little to resolve the structural weakness exposed by the attack. All 15 federation entities had simply trusted Blockstream's software update without running independent code audits or establishing withdrawal circuit breakers.
The failure highlights the systemic risks of software homogeneity in decentralized finance. Multi-sig federations are designed to prevent single points of failure, but when every signer runs identical software, a single code flaw bypasses the entire multi-party consensus. SideSwap processed the massive withdrawal without basic identity verification or volume limits, allowing a single invalid proof to nearly wipe out sidechain reserves.
Federated custody promised decentralization. A single unmerged patch exposed it as a single point of failure.
Source Intelligence
- Deep dive into what was said in the episodes
Blockstream Liquid's $320M Hack, Open Source AI Summit Takeaways, Vora Reveal • Sep 11
- Blockstream Liquid was hacked for 4,000 BTC after an attacker exploited an inflation vulnerability. The exploit resulted from a flawed code patch released on September 1, 2024, which attempted to fix an older 2018 range proof vulnerability.
- Adam Back announced the Liquid network peg will remain one-for-one. Blockstream and its partners are plugging the remaining 600 BTC deficit after the hacker returned 3,400 BTC through encrypted OP_RETURN negotiations, keeping 15 percent as an unsolicited bounty.
Also discussed on this episode: (6)
Protocol (1)
- The Liquid exploit exposed structural risks in federated sidechains, where members blindly run software updates without auditing the code. The attacker bypassed security controls by exiting through Sideswap, a federation member that lacked KYC or transaction velocity controls.
Safety (1)
- An Anthropic employee's public exit over existential AI risk was an orchestrated media campaign designed to trigger regulatory capture. David Sachs argues that coordinated media coverage and political reactions aim to build regulatory barriers that protect closed labs while stifling open-source models.
Open Source (1)
- Attempts to restrict open-source AI development in the United States fail to account for China's pro-technology momentum. David Sachs points to data showing 83 percent of China's population holds a positive sentiment toward AI, viewing it as an economic tool rather than an existential threat.
Models (1)
- Ramez Naam demonstrated that OpenAI's technological lead has collapsed from 20 months in 2022 to just five months. This rapid convergence shows that AI development is heading toward a plurality of models rather than a single monopolistic winner.
Agents (1)
- Open protocols are essential to prevent vendor lock-in as autonomous AI agents proliferate. Builders at the summit highlighted open-source memory protocols as a critical mechanism to let users export their local context and memory across different models.
AI Infrastructure (1)
- Vora revealed its local AI hardware device featuring a mid-century wooden aesthetic and 64 gigabytes of RAM. The device serves as a local security membrane, allowing users to store memory and context locally while securely managing API calls to external cloud models.
4000 BITCOIN HACKED | THE BITCOIN BRIEF 89 • Sep 8
- An attacker drained nearly 4,000 Bitcoin from the Liquid Network after exploiting a software bug that accepted fake liquid Bitcoin as valid. Side swap accepted the coins, and the federation processed a peg-out of roughly 3,996 Bitcoin to the attacker.
- The Liquid federation's 11-of-15 multi-sig custody structure failed to stop the exploit because the underlying software validated the fake coins first. Since all signers ran the same faulty Elements code, they reached the same incorrect validation conclusion.
- The attacker communicated with Blockstream via on-chain OP_RETURN and PGP-encrypted messages, claiming they would return the funds once all nodes are patched. Max remains skeptical of a return, while q and a expects the attacker to comply.
Also discussed on this episode: (11)
Protocol (1)
- The Liquid exploit targeted a validation shortcut in the Elements software cache. The cache verified range proofs without validating asset types or spending conditions, allowing the attacker to bypass cryptographic checks with an invalid output that matched a cached description.
Coding (1)
- Orange Surf reports that the vulnerability was publicly exposed when a patch pull request sat open starting September 1. The attacker likely identified the unmerged bug fix and immediately exploited the live network.
Custody (4)
- Foundation released KeyOS 1.4 for Passport Prime, enabling app sideloading verified by developer certificates. The update allows custom security profiles, with plans for a whitelisted and vetted Foundation App Store to aid less technical users.
- Chilean exchange OrionX halted withdrawals after a forensic audit revealed $7 million in customer crypto was missing. Founding partners are accused of conducting unauthorized speculative trading with user funds without operating licenses between 2018 and 2021.
- The hacker responsible for the Wave 3 Coldcard exploit moved roughly 20.5 Bitcoin into Ethereum via Thorchain swaps. This constitutes slightly over 1 percent of the total 1,789 Bitcoin stolen during the exploit.
- Cake Wallet 6.4.4 added native Trezor support for cold storage, while Nunchuk added BitBox02 Bluetooth connectivity. Additionally, RoboSats Alpha 0.87 added three new coordinators and encrypted image uploads through Noster Blossom servers.
BTC Markets (1)
- CoinDesk reports that the Bitcoin-backed mortgage product offered by Better and Coinbase allows the lender to rehypothecate borrower collateral. This gives Better the right to reuse the pledged Bitcoin in secondary financial agreements, introducing additional counterparty risk.
Privacy (2)
- Trezor's shipping partner, ShipMonk, leaked customer records of approximately 67,000 US customers, bringing the total exposed to 80,000. The leak included names, physical addresses, phone numbers, and email addresses, highlighting shipping data risks.
- Pocket Bitcoin suffered a support system breach that exposed compliance records for 291 EU customers and bank transfer details for over 5,000 users. This breach directly links real-world identity data to public Bitcoin transaction histories.
Stablecoins (1)
- Two Thai businessmen are suing Tether for freezing $42.4 million in USDT across ten Ethereum addresses. The plaintiffs allege Tether executed the freeze based on an informal verbal request from Homeland Security, months before a warrant was issued.
Regulation (1)
- The US House canceled its late September voting sessions, narrowing the window to pass the Clarity Act before the midterm recess. A critical procedural vote requiring 60 votes to advance the regulatory bill is set for September 15.

