Price:

Attacker demands $50M ransom after Liquid sidechain exploit

Sep 17, 2026Summary from 3 podcasts.
  • A consensus bug let an attacker print $320 million on Blockstream's Liquid sidechain.
  • The hacker returned 85 percent of funds but kept 600 Bitcoin as ransom.
  • Federation signers ran Blockstream's software patch without running independent audits.

A single transaction exposed the fragile foundation of federated sidechains.

When an attacker exploited a consensus vulnerability on Blockstream's Liquid network, 4,000 synthetic Bitcoin were generated out of thin air. The breach siphoned $320 million through Sideswap, a federated trading venue operating without withdrawal throttles or identity checks. The underlying flaw stemmed from a recent software patch designed to fix a previous bug, which deployed without scrutiny across the network's 15 federated operators.

The attacker subsequently attached metadata to an on-chain transaction claiming whitehat status before offering to return the bulk of the haul. After returning 3,400 Bitcoin, the hacker retained 600 Bitcoin as a forced 10 percent bounty fee. On Stacker News Live, host Keon rejected the whitehat label entirely, arguing that withholding funds involuntarily is simple extortion. PGP-encrypted negotiations between Blockstream and the attacker ultimately broke down when the hacker threatened to publish private communication logs on the public ledger.

The breach triggered sharp critique across the Bitcoin ecosystem regarding software governance. Discussing the incident on Ungovernable Misfits, host Max argued that Blockstream got lucky the hacker returned any collateral at all. Max emphasized that the consensus vulnerability had sat unpatched despite prior warnings, revealing systemic maintenance oversights within institutional Bitcoin infrastructure providers.

The exploit undermines a core marketing premise of federated sidechains: that distributing signers across multiple independent entities mitigates single points of failure. In practice, all 15 Liquid federation signers ran Blockstream's flawed software update without running independent code audits. That blind trust transformed a software bug into an instant network-wide drain.

Moving 600 stolen Bitcoin presents its own technical hurdles. While attackers frequently route funds through CoinJoin mixers, ThorChain bridges, and privacy pools, on-chain analytics continue to narrow obfuscation vectors. As noted on Stacker News Live, stolen funds remain permanently visible on a public ledger, leaving the hacker vulnerable to eventual identification when attempting to cross fiat exit ramps.

Federated multisigs offered convenience, but convenience without independent verification remains an expensive illusion.