Blockstream has refused to pay for the return of Bitcoin after a theft from the Liquid Network because it believes that security researchers should not steal!

Most of the funds have already been returned, but nearly 600 $BTC, which is worth about $47 million, remains with the people behind the attack.

How the Liquid Network hack unfolded

The incident began when attackers found a flaw in software used by Liquid, a Bitcoin-based network designed to support faster transfers and other financial services.

Through the weakness, around 4,000 Liquid Bitcoins were generated, which were then exchanged for the real Bitcoin on the network. They [the attackers] described what they did as “white-hat” activity, and about 3,400 $BTC was returned afterwards.

But Blockstream said that the negotiation it had before with the people behind it was just to get users’ funds back, and that it should not be interpreted as accepting their actions or demands.

Blockstream draws a line over the remaining bitcoin

In a public statement, Blockstream declared that it would not be paying a ransom to recover the remaining funds.

Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.

Blockstream said they were not going to pay, stating that paying would create a bad precedent for those who develop open-source software. Instead, it promised to aid law enforcement, exchanges, and $BTC blockchain investigators to find the $BTC that had not yet been seized and trace those responsible for the attacks.

Blockstream ended the statement with a direct demand: “Return the bitcoin.”

Bitcoin community questions Blockstream’s position

The refusal has divided some members of the Bitcoin community.

Whale Coin Talk wondered if the situation could have been worse still and pointed out that the funds were returned, so it was an actual white hat, as another group might never have given them back.

Seems like white-hat hackers are doing a better job than protocols at keeping users safe.

Others focused on Blockstream’s responsibility for the vulnerability. Kurt Wuckert Jr. summarized that criticism by writing:

Code is law when it benefits us, but law is law when our code gets people robbed.

All these do not answer the questions of whether the attackers are security researchers, and show why the case became more than a crypto hack. It also raises the issue of when unauthorized testing can be called extortion.

Final Summary

  • Blockstream says it will not pay for the return of nearly 600 $BTC still held by the attackers.
  • The partial return of approximately 3,400 $BTC has caused disagreement over whether the incident involved white-hat research or theft.