Hackers who pulled roughly $320 million in Bitcoin from Blockstream’s Liquid Network on September 6 have gone public with their demands. They moved from encrypted messages to open plaintext ultimatums posted on the Bitcoin blockchain and now insist on a 10% bounty paid from the company’s own funds.

How the Exploit Worked

The attack relied on a range-proof verification cache bug in Elements, the open-source software that powers the Liquid sidechain. Blockchain security firm Chainalysis identified the flaw. It let the attackers mint unbacked L-BTC tokens that the system treated as valid. Those tokens were then converted into real Bitcoin through SideSwap’s peg-out service.

Roughly 4,000 BTC left in a single transaction. That amount equaled about 95% of the federation wallet’s reserves, according to Reuters. No federation keys were compromised. Liquid runs on an 11-of-15 multisig setup, and the multisig itself held. The breakdown happened in the upstream validation software.

SideSwap’s automated system processed the withdrawal without size or velocity checks. The exchange later accepted responsibility for turning a Liquid-layer fault into a mainchain loss and returned its roughly 4 BTC fee to the federation.

Partial Return and the Standoff

Blockstream patched the vulnerability and updated its nodes. The attackers then returned 3,400 BTC. They kept 598.5 BTC, worth about $47 million at the time, as a self-appointed reward.

Early talks happened through PGP-encrypted OP_RETURN messages on the Bitcoin blockchain. Those exchanges soured. The hackers sent a two-character plaintext note—“:(”—and announced that all future messages would stay unencrypted.

The Public Ultimatum

In a Bitcoin transaction the attackers accused Blockstream of putting as little as $1.5 million toward securing $5 billion in assets. Their message read: “You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess.”

The 10% figure suggests they are ready to return more of the remaining funds and keep roughly $32 million instead of the full $47 million they still hold.

Industry Pushback

The white-hat framing drew sharp criticism. Ledger CTO Charles Guillemet called the demand “straight extortion.” He argued that responsible disclosure would have meant contacting Blockstream’s security team privately so the network could be paused and patched before any funds moved.

Bitcoin Core contributor Greg Sanders dismissed the hackers’ complaints about spending: “Robbing a fancy bank, trying to keep a double digit percentage and accusing others of greed. Ok buddy.”

Blockstream’s Response

Blockstream released an emergency Elements v23.3.4 patch and said functionary nodes are being updated. The recovery plan calls for resuming block production with peg operations frozen, replaying verified transactions, and then restarting pegs once the network state is restored.

The company also warned that scammers are already impersonating Liquid. Users should treat unsolicited outreach, “claim L-BTC” sites, and any requests for recovery phrases as fraudulent.