Blockstream got an ultimatum this week: pay a "bug bounty," or bitcoin holders on its network eat a bigger loss. On Thursday, the company gave its answer in five words: not a single satoshi.
The saga started on September 6, when someone found a flaw in Elements, the software behind Liquid — Blockstream's bitcoin sidechain used by exchanges and stablecoin issuers like Tether for faster settlement. The attacker minted roughly 4,000 unbacked L-BTC tokens, coins with no real bitcoin behind them, then routed them through SideSwap, a federation member with withdrawal rights, to cash out into actual BTC. At the time, that haul was worth about $320 million.
A day later, on September 7, the attacker abruptly sent back around 3,400 BTC, attaching an on-chain note: fix the bug first, then you'll see the rest. Blockstream patched the flaw within days and restored block production on September 10, though deposits and withdrawals on Liquid remain frozen.
The remaining 598.5 BTC — about $47 million — never came back. Instead, the attacker sent a bill: a 10% cut of the original haul, framed as a bug bounty, with a warning that refusing would cost token holders 15% of their value. Blockstream wasn't buying the framing. "We will not pay a ransom for the return of stolen funds," the company said. "Taking assets without authorization and withholding their return is a crime, not responsible disclosure." It says it's now working with law enforcement, exchanges and forensics firms to trace the coins.
The contrast with past hacks is hard to miss. When Poly Network lost $610 million in 2021, the hacker returned almost everything voluntarily and was later offered a job as the protocol's chief security advisor — no threats involved. Here the roles are reversed: the attacker set their own price and threatened consequences if it wasn't paid. How this plays out matters beyond Liquid — cave once, and the next sidechain hack comes with the exact same invoice attached.



