Friday, Sep 11, 2026
1 Blockstream Rejects 10% Ransom for 600 BTC From $320 Million Liquid Exploit↩︎ 🪙 Crypto Sep 11, 7:00 AM EDT 15/10
The company is seeking the return of 598.5 BTC through law enforcement and forensic specialists after denying a payout to hackers. Blockstream argued that withholding assets constitutes theft rather than white-hat activity, despite the attacker having already returned 3,400 BTC—roughly 85% of the funds—from a $320 million exploit. SlowMist founder Cos described the refusal of the 10% bounty demand as puzzling, suggesting there may be undisclosed communications between the parties.
The September 6 attack targeted a cache key collision vulnerability in rangeproof verification, which enabled an attacker to mint 3,998.5 L-BTC without a corresponding peg-in. These tokens were converted into real BTC on the mainnet within minutes. SlowMist identified the root cause as the Elements software concatenating variable-length fields without length prefixes, causing the system to skip cryptographic verification for the fake UTXOs.