Keon rejects Liquid hacker whitehat claim after breach
- Blockstream's Liquid network lost 4,000 Bitcoin after federation members approved an un-audited consensus code patch.
- The attacker returned 85 percent of stolen funds but retained 600 Bitcoin as a bounty fee.
- Stacker News Live host Keon rejected whitehat labels, calling the retained funds outright extortion.
Federated sidechains were supposed to solve Bitcoin scaling without compromising security.
A single flawed consensus patch on Blockstream's Liquid network drained 4,000 Bitcoin worth $320 million. The vulnerability allowed an attacker to artificially inflate an account balance and route the payout through Sideswap, a federated operator lacking withdrawal limits and identity checks. All 15 federation entities approved the code update without running independent code audits.
When the hack was discussed on Presidio Bitcoin Jam on Sep 11, 2026, the initial focus centered on how single-point reliance on Blockstream's software broke the federation's core trust model. The attacker returned 85 percent of the funds on-chain while keeping 600 Bitcoin, framing the retained millions as a legitimate whitehat security fee.
Two days later on Sep 13, 2026, the narrative hardened during Stacker News Live. Host Keon rejected the whitehat framing entirely, classifying the retained 600 Bitcoin - worth roughly $48 million - as simple extortion. PGP-encrypted negotiations broke down after the attacker threatened to publish plain-text communication logs directly on-chain.
Siphoning off stolen collateral is one thing; spending it on public ledgers is another. On Stacker News Live, the technical conversation turned to laundering constraints. Attackers frequently attempt obfuscation through CoinJoin mixers, ThorChain bridges, and Ethereum pools, but on-chain analytics continue closing in on complex routing schemes. Keon noted that while local AI models might help attackers check privacy leaks at each hop, technical execution eventually hits the wall of fiat exchange surveillance.
The incident lays bare the structural weakness of hot multisig federations. Relying on 15 trusted entities offers little protection when every node blindly signs off on identical code updates. Restricting withdrawal limits or introducing manual circuit breakers might slow automated drains, but federated models remain inherently reliant on operational discipline across all members.
Without independent code audits, multi-sig federations are just central authorities with extra steps.