Blockstream has confirmed it will not pay a ransom to recover approximately 4,000 BTC stolen from the Liquid Network in a September 6 exploit, characterizing the act as theft rather than responsible vulnerability disclosure. Over 3,400 BTC, representing roughly 85% of the total, has already been returned to the network.

Refusal to Negotiate with Attackers

The company stated in a public announcement that it will not use user funds to pay a ransom or set a precedent requiring open-source developers to compensate attackers for returning stolen assets. Blockstream emphasized that unauthorized seizure and withholding of Bitcoin constitutes a crime, not white-hat activity.

Blockstream noted that negotiations with the fund holders have been conducted in good faith to secure the return of user assets, reiterating a direct call for the attackers to “Return the bitcoin.”

Breach Originated from Elements Software Bug

The attacker transferred the majority of the stolen Bitcoin in a single transaction on September 6. Blockstream confirmed the breach resulted from a bug in Liquid’s underlying software, Elements, rather than a leak of private keys. Following the deployment of a corrected software version, block generation resumed on September 10, though the peg-out function remains suspended as a precaution.

Commitment to Legal and Forensic Recovery

Blockstream announced it will collaborate with law enforcement, exchanges, payment service providers, and forensic experts to trace the remaining funds, leveraging Bitcoin’s transparent transaction history. The company framed its refusal as a stand against establishing a precedent that could burden open-source developers with ransom demands far exceeding their financial interest in a project.

Implications for Layer-2 Security

The incident underscores the security risks inherent to Bitcoin sidechains and layer-2 infrastructure, even when a significant portion of stolen funds can be recovered without ransom. Blockstream’s stance may influence how other open-source projects respond to future extortion attempts.

Source link

Exit mobile version