Arc mainnet is live — chain ID 5042, RPC & first steps →LIVEArc Launchpad — Bullcheese.fun from TrustSwap →LAUNCHING
Back to Blog

A Hacker Kept 598 Bitcoin and Called It a Consulting Fee

Onuora Amobi·October 2, 2026
Blockstream
Liquid Network
crypto security
bitcoin bridge
white hat bounty
A Hacker Kept 598 Bitcoin and Called It a Consulting Fee

Somewhere along the way, crypto invented a tipping convention for people who steal from it.

On September 6, attackers describing themselves as whitehats pulled close to 4,000 BTC out of the federation wallet behind Blockstream's Liquid Network, roughly $320 million at the time. Most of it came back. About 3,400 BTC was returned within days. The remainder — roughly 598.5 BTC — is still held by the group, which has framed the shortfall as its fee. Ten percent of the take, self-assessed, non-negotiable.

Blockstream said no. In its words, withholding the coins "is a crime, not responsible disclosure," and the company intends to work with law enforcement, exchanges, and forensic firms rather than settle.

That refusal is more interesting than the hack.

The bug was in the privacy, not the multisig

Liquid was built to be the conservative option. A federated sidechain, coins held under a large multisignature arrangement operated by known exchanges and businesses, deliberately boring compared to the trust-minimized bridges that have been draining money since 2021. The federation wasn't the failure point.

The failure was a cache-key collision in the confidential transaction verification path — the machinery that lets Liquid hide transaction amounts while still proving they balance. Two distinct things hashed to the same cache entry, and the verifier accepted work it should have rejected.

Read that again, because it is the uncomfortable part. The feature that made Liquid attractive to institutions — amount privacy — is what broke. Not the key management. Not the signer set. The cryptographic optimization underneath a privacy guarantee, in code that has been reviewed by people who are very good at reviewing code.

"White hat" used to describe conduct, now it quotes a price

There was a time when white hat meant you found the bug, told the maintainer, and got paid whatever the program offered. The category has drifted. It now routinely describes someone who takes the money first and then opens a conversation about what percentage they'll keep, with the implicit threat that the alternative is zero.

Compare two incidents from the same week. On September 11, the same day Blockstream went public with its refusal, Symbiosis halted its Bitcoin bridge after an exploit and offered the attacker a 20% white hat bounty on recovered funds, valid until September 13. One project publishes a price. The other declines to meet one.

Both are rational. Symbiosis is small enough that 80% of something beats 100% of a forensic investigation. Blockstream is large enough, and institutional enough, that paying would establish a rate card it will be quoted back for years.

And here's the part nobody enjoys saying out loud: the projects that pay are why the projects that don't now have a harder time. Every negotiated settlement is a data point telling the next attacker that extraction is a pricing exercise with an expected value attached. The industry built that expectation transaction by transaction, mostly out of pragmatism, each time believing it was making a one-time exception.

Insurance would fix this, and nobody has built it

Traditional finance solved the equivalent problem with a boring mechanism: insurance and a legal system that makes ransom payment expensive or illegal. Ransomware policy in most jurisdictions has moved hard against paying, precisely because payment funds the next attack.

Crypto has no equivalent. Coverage for protocol failure is thin, expensive, and largely unavailable at the scale of a $320 million federation wallet. So the negotiation is the insurance, and the attacker writes the policy.

What can't be negotiated with is what actually holds

The structural lesson isn't about better audits. Audits found nothing here for a reason — a cache-key collision is the kind of defect that survives every review that assumes the primitive underneath is sound.

The lesson is narrower. Systems that can be persuaded will eventually be persuaded. Systems where there is no counterparty to talk to are the ones that hold under pressure, which is why the least glamorous parts of the stack keep outperforming the clever parts. A time-locked contract has no negotiating position. A vesting schedule doesn't consider offers. Teams using Team Finance to lock liquidity or stage a token unlock aren't buying sophistication; they're buying the absence of a conversation, which turns out to be the more durable property.

That principle scales poorly to sidechains holding hundreds of millions in custody. Federations have humans. Bridges have upgrade keys. Every one of those is an address where a demand can be delivered.

Recovery is the wrong metric

Eighty-five percent came back, and the headline number will read as a partial success. It shouldn't. A $320 million compromise that resolves into a $48 million loss and a public standoff is not a win — it's a system discovering that its worst outcome was capped by the attacker's own preference for a clean exit.

Next time the attacker may not want a clean exit. State-linked groups have already demonstrated that they'll take the whole balance and skip the etiquette entirely, and they have no interest in a reputation among security researchers.

Blockstream's refusal will cost it 598 BTC and some awkward quarters. What it buys is harder to price: one large operator declining to confirm that theft has a standard commission. The question now is whether anyone else in the industry backs that position when the invoice arrives at their own door — or whether they quietly pay, as almost everyone has, and let Blockstream hold the line alone.

Share
Back to Blog