Price:

Keon calls Liquid hacker an extortionist

Sep 15, 2026Summary from 4 podcasts.
  • Liquid’s 15-member federation trusted one flawed software update.
  • The attacker returned 85% but kept roughly $48 million.
  • Keon says a forced finder’s fee is extortion, not whitehat work.

Liquid’s federation did not fail at signing. It failed at software consensus.

On Sep 8, Ungovernable Misfits described how a caching shortcut in Elements, the software behind Liquid, let an invalid confidential-transaction proof pass validation. The cache failed to preserve crucial context about asset types and spending conditions. SideSwap then accepted roughly 4,000 forged LBTC and routed the withdrawal through Liquid’s normal peg-out process, leaving the attacker with nearly 4,000 real Bitcoin.

David Bennett made the next implication explicit on Bitcoin And: automated tools now compress the distance between a coding mistake and a working exploit. The attacker returned 3,400 BTC after Blockstream patched its bridge nodes but kept 598.5 BTC, worth about $48 million according to the show’s Sep 8 account. That turned a software failure into a negotiation over the price of recovery.

"Automated tools now scan code repositories continuously to construct exploits faster than human auditors can identify flaws."

- David Bennett, Bitcoin And | Bitcoin & Economic News

The federation’s structure offered little protection because all 15 members relied on the same faulty consensus view. Presidio Bitcoin Jam reported on Sep 11 that a fix for the caching flaw had already appeared in a public pull request weeks before the attack, but nodes had not merged it. The failure was therefore shared, not independent: eleven signers could authorize the peg-out while each believed the transaction valid.

The whitehat label became the second fight. Presidio Bitcoin Jam called keeping 600 BTC against Blockstream’s wishes extortion. On Sep 13, Stacker News Live host Keon rejected the attacker’s demand for a voluntary bounty and said Blockstream threatened prosecution unless every satoshi was returned.

"Keeping $50 million against the owner's consent is extortion, regardless of how polite the blockchain messages were."

- Keon, Stacker News Live

The latest discussion shifted from recovery to whether the stolen coins can be spent. Stacker News Live described movements through CoinJoin, ThorChain and Ethereum pools, but noted that exchange surveillance and fiat exit points still expose attackers to identification. Cross-chain routing can obscure the trail; it does not erase the permanent record or solve the final cash-out problem.

The incident also exposes a limit in the word “federated.” Liquid’s 11-of-15 signing arrangement distributes custody, but it does not distribute software risk when every signer runs the same unverified update. Blockstream restarted the chain and patched the gap; what remains unresolved is whether independent audits, withdrawal limits and stricter disclosure processes can prevent the next consensus bug from becoming another negotiated ransom.

The lesson from a week of coverage is narrow and damaging: multisig can prevent one operator from stealing funds, but it cannot rescue a federation that shares one broken definition of reality.