News linked to both this project and an event.
Odaily News — Multiple Bitcoin ventures associated with Bitcoin pioneer and Blockstream co-founder Adam Back have recently suffered a series of setbacks: the merger between BSTR Holdings, the Bitcoin treasury project he championed, and a SPAC under Cantor Fitzgerald has been terminated, with BSTR ordered to pay a $15 million breakup fee; Blockstream Mining, the Bitcoin mining operation he co-founded and in which he holds a minority stake, along with its partner Exacore, has faced multiple lawsuits following its spin-off from Blockstream, accused of owing equipment payments, electricity bills, and customer deposits, with related financing totaling approximately $2 billion; meanwhile, Liquid Network, the Bitcoin sidechain initiated by Blockstream, suffered a hack in which approximately 4,000 BTC were stolen, of which 3,400 have been returned, with the hacker still retaining approximately $47 million worth of Bitcoin. (Bloomberg)
Odaily News: Canadian Bitcoin exchange and wallet company Bull Bitcoin stated that due to the Liquid Network attack on September 6, users are temporarily unable to redeem L-BTC back to Bitcoin through the platform, and redemption operations are still pending resumption.Bull Bitcoin expects the related redemption service to potentially resume within 30 days, but stated that this expectation is not guaranteed. Due to its reliance on the L-BTC redemption mechanism to balance inventory, the platform has temporarily closed inbound Lightning Network payments.In this attack, the attacker transferred out nearly 4,000 Bitcoin from the protocol, later returning approximately 3,400; currently still holding 598.50 Bitcoin, valued at over $51 million. Liquid Network stated on September 17 that block production, network transactions, and L-BTC transfers have returned to normal. (Bitcoin.com News)
Odaily News: The Liquid Network attacker has returned 3,400 bitcoins after the September 6 exploit, accounting for approximately 85% of the transferred assets; they currently still hold 598.50 bitcoins, worth over $45 million.Blockstream, the digital asset infrastructure company responsible for maintaining the Liquid Network, has refused to pay a ransom for the remaining assets and is demanding the return of the relevant bitcoins. The network shows 4,234.76 L-BTC in circulation, while the bitcoin reserves stand at only 3,632.23.The L-BTC-to-bitcoin redemption function has still not been restored, with Sideswap stating that redemptions are currently unavailable; Blockstream founder Adam Back said that L-BTC will be backed 1:1 by bitcoin reserves and reminded holders not to sell L-BTC off-market at a discount.As of now, Blockstream has not yet issued an announcement that "redemptions are live." The attacker's wallet continues to receive on-chain messages and has been subjected to address poisoning attacks and scam messages, with the related attacks inducing transfers by generating visually similar addresses. (Bitcoin.com News)
According to Bitcoin News monitoring, JAN3 has stated that its newly launched swap infrastructure Indra has suffered a denial-of-service attack, and the team has temporarily disabled forward swaps while investigating. Swaps already in progress may experience delays. Indra, developed by JAN3, is designed to replace Boltz in Aqua, enabling users to move Bitcoin between Lightning and Liquid, though Liquid peg operations remain restricted.
Bitcoin News posted on X platform stating that Samson Mow said Blockstream refuses to pay a ransom and does not rule out offering a bounty if the hacker returns the remaining stolen funds. Mow stated that the stolen funds belong to Liquid users, and Blockstream cannot negotiate over these funds; any bounty would need to be an independent and reasonable arrangement.
Odaily News: According to Bitcoin News monitoring, its latest newsletter reviewed multiple security incidents over the past eight weeks involving projects that Bitcoin users rely on in their daily activities, with a focus on the latest major exploit targeting Liquid Network.
Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)
SlowMist has disclosed that the Liquid Network was attacked on September 6 via a Rangeproof verification cache key collision vulnerability. The attacker minted approximately 3,998.5 L-BTC without collateral — with no corresponding BTC peg-in — and then within minutes converted them to BTC on the Bitcoin mainnet via peg-out. After the incident, approximately 3,400 BTC was returned to the Liquid Federation peg wallet, but approximately 598.5 BTC remains under the attacker's control.SlowMist noted that the root cause of the vulnerability lies in the fact that the Rangeproof verification cache key in Elements did not include length prefixes when concatenating multiple variable-length fields, allowing different parameter combinations to potentially generate the same cache key. The attacker triggered a cache collision by constructing transactions, causing nodes to hit a "verification passed" cached result, thereby bypassing secp256k1_rangeproof_verify and the minimum amount check, ultimately accepting outputs not backed by real assets and completing the L-BTC minting. SlowMist stated that it has traced the fund flows on the Bitcoin side and completed its analysis of the incident.
Blockstream officially announced on the X platform that Liquid Network has suffered a Bitcoin theft incident. The company explicitly stated its refusal to pay any ransom and characterized the act as a crime rather than a white-hat disclosure. Blockstream has collaborated with law enforcement agencies, exchanges, forensic experts, and other parties to trace the stolen assets through on-chain tracking and other means. It also called on current holders to voluntarily return the Bitcoin, warning that they will face full legal action otherwise.
Bitcoin News posted on X stating that Samson Mow and Bitcoin Red Team researcher Calle are engaged in a public dispute over whether security warnings related to a Liquid Network exploit were properly handled. Calle claims that Blockstream did not act on the Red Team's email, ultimately resulting in a loss of 600 BTC; Mow responded by saying "no email was ignored." Calle stated that once Blockstream restores normal Liquid operations and publishes a post-mortem report, the Red Team will release a full account of the disclosure process. Mow separately warned against blindly trusting AI-generated security reports, saying that unverified fixes could introduce new vulnerabilities, and criticized researchers who prioritize pursuing "clout" over protecting Bitcoin.
Liquid Network resumed empty block production after deploying an emergency patch, following a core software vulnerability that resulted in nearly $320 million in assets being withdrawn. Asset recovery and system stability monitoring are currently ongoing.
according to Bitcoin News monitoring, Samson Mow has warned the alleged white hat hacker behind the Liquid attack that they may have left behind more clues than they realize. Mow stated, "The net of justice is wide and inescapable; no one will be spared." Mow also questioned the attacker's demand to return Bitcoin in exchange for a bounty, asking whether it is wise to publicly admit to taking Bitcoin and demand a bounty in return. Mow pointed out that Liquid's approximately $5 billion in assets, including L-BTC, Tether, and real-world assets, all belong to their respective issuers and holders, and cannot be used as a basis for calculating a bounty. Regardless of how other matters are negotiated, all user assets must be fully returned.
Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.
According to Odaily Planet Daily, as monitored by Bitcoin News, the white hat hacker group behind the Liquid exploit has accused Blockstream of spending only $1.5 million—or possibly nothing at all—to secure $5 billion in assets. In a new on-chain message, the group demanded that Blockstream allocate its own funds to pay a bug bounty equivalent to 10% of the associated assets, warning that refusal to pay would result in a 15% loss for holders. The group also stated it would release the private keys used to decrypt previous communications with Blockstream. Earlier, the group had returned 3,400 BTC to the Liquid Federation, with approximately 600 BTC still unrepaid.
Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.
Odaily News, according to Bitcoin News, Blockstream stated that Liquid Federation members are preparing to coordinate a network restart, with the updated software already deployed. Previously, a security incident occurred on the Liquid Network, resulting in fund transfers. Blockstream noted that its team remains focused on further strengthening the network and ensuring asset restitution. Blockstream thanked the Bitcoin community for its patience, support, suggestions, and assistance, and stated that more updates will be released in the future.
According to on-chain monitoring by analyst PeckShield (@PeckShieldAlert), the Liquid Network was targeted by white-hat hackers. Approximately 4,000 BTC (roughly $320 million) were transferred from a Liquid Federation wallet. The funds were consolidated into address bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, accompanied by an on-chain message: "We are white hats, please contact us on-chain." Subsequently, the hackers completed on-chain negotiations with Blockstream, returning 3,400 BTC (approximately $315 million, or 85% of the total) while retaining around 598.5 BTC (about $47.38 million) as a bug bounty.
Odaily News: Blockstream has notified white hat hackers that the vulnerability fix is complete and the approximately 4,000 BTC can be safely returned. The hacker who previously withdrew funds from the Liquid network expressed willingness to return them, but requested that the vulnerability be fixed first. Both parties have been negotiating publicly through Bitcoin OP_RETURN messages.The hacker initially proposed returning "most" of the BTC, but later changed their stance, demanding that the vulnerability be fixed first: "Ensure every node has been patched, and once the fix is confirmed, we will securely return the funds." The hacker also sent encrypted vulnerability details to Blockstream. About two hours ago, Blockstream responded via a PGP-signed OP_RETURN message stating that nodes have been patched. Currently, 3,998.5 BTC remain under the hacker's control.
According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.
According to an announcement from the official Liquid Network X account (@Liquid_BTC), a suspected whitehat hacker withdrew approximately 4,000 BTC worth around $320 million from a Liquid Federation wallet using a SideSwap PAK (Peg-out Authorization Key). The official statement indicated that the key itself was not leaked, and the Blockstream team is attempting to contact the party through on-chain signed messages. Following the incident, exchanges have paused or are about to pause LBTC deposit and withdrawal services. Bridge nodes have been temporarily shut down, and the Liquid sidechain is currently suspended, unable to submit new transactions. Officials emphasized that other Liquid assets such as USDT, DePix, and RWA remain unaffected by this incident, while Federation members are actively working to resolve the issue to restore normal network operations as soon as possible.