NextFin News - A $320 million exploit on Blockstream's Liquid Network, a $6.7 million breach-of-contract lawsuit against a Blockstream-affiliated miner, and the collapse of a planned Nasdaq-listed bitcoin treasury vehicle have converged on Adam Back's crypto empire within a single month, testing the reputation of the company that has spent more than a decade positioning itself as the safest infrastructure layer in digital assets.
The Liquid Network, a bitcoin sidechain launched in 2018 by Blockstream and used by exchanges including BTSE, Bitfinex and BitMEX to settle transactions faster and more privately than the base bitcoin chain allows, said on September 6 that roughly 4,000 of the 4,200 bitcoin held in its federation wallet - about $320 million - had been withdrawn in a hack. The network halted all new transactions almost immediately, and exchanges suspended deposits and withdrawals of Liquid Bitcoin, or L-BTC, while the federation investigated.
Within days, attackers who identified themselves as "white-hat hackers" returned about 3,400 BTC, roughly $272 million, or 85 percent of the stolen funds, after Blockstream patched the underlying software flaw. But roughly 598.5 BTC, worth about $47 million, remains with the attackers, and Blockstream has refused to negotiate for its return, calling the demand "theft." The incident ranks as the single largest cryptocurrency theft of 2026, ahead of the April thefts from KelpDAO and Drift.
The hack is only one front in a difficult September for Back, Blockstream's co-founder and chief executive. On September 11, River Financial filed a lawsuit in the Northern District of California against Blockstream Services Canada ULC seeking about $6.7 million over a canceled bitcoin-mining contract, and in August a planned merger that would have taken Back-led BSTR public with a 30,021 BTC treasury collapsed, leaving a $15 million termination payment with deadlines on September 19 and December 1.
The central question is whether these events amount to a cyclical reputational shock that Blockstream can absorb - the largest bitcoin-sidechain hack yet, but one in which 85 percent of funds were recovered within 48 hours - or whether they expose a structural weakness in the federated infrastructure model that Blockstream has championed as safer than the alternatives. The answer matters because Liquid is not a marginal experiment: it is plumbing that major exchanges rely on to move bitcoin off the main chain, and its security model depends on software correctness and a federation of signers rather than bitcoin's own proof-of-work consensus.
The Exploit: How $320 Million Left a Wallet That Was Never Supposed to Be Emptied
The attack did not break into Liquid's vault in the conventional sense. Instead, it exploited a flaw in Elements, the open-source validation software that underpins the Liquid sidechain and that Blockstream maintains. Liquid works by locking real bitcoin with a federation of signers, minting an equivalent amount of L-BTC on the sidechain, and burning L-BTC to redeem bitcoin through a "peg-out" approved by an 11-of-15 multisig. To keep verification fast, Elements caches the results of range-proof checks - cryptographic attestations that a confidential output's value falls within a valid bound. Without that check, a transaction can create spendable value from nothing.
Reconstructions by blockchain-intelligence firms and independent analysts show the sequence in granular detail. At 13:53 UTC on September 6, in block 4,050,336, the attacker minted about 4,000 L-BTC with no backing. At 14:06 UTC they requested a withdrawal through SideSwap, an approved settlement operator. At 14:28 UTC the federation paid out about 4,000 BTC. From mint to payout took 36 minutes, and roughly 3,996 BTC reached the attacker. The federation's signers approved the withdrawal because Elements treated the chain state holding the unbacked L-BTC as valid.
SideSwap said the unbacked L-BTC came from an Elements software bug rather than a compromise of its own systems, and Blockstream said none of its signing keys were compromised. That distinction - a validation bug rather than a stolen key - is precisely the line Blockstream has drawn in its public response. The company framed itself as Liquid's "technical provider" working with the federation to resolve the situation, rather than as the custodian of the drained reserve.
"Following the recent incident affecting the Liquid Network and the movement of funds, Blockstream, as Liquid's technical provider, and the Liquid Federation have been working diligently to resolve the ongoing situation and ensure the return of assets. Updated software has been…"
The attackers, for their part, opened a public negotiation on the bitcoin blockchain itself, embedding the message "we are whitehats. contact us on chain" in the OP_RETURN field of a transaction. They promised to return the funds once every node patched the bug. Once the patch went out, the returns began - about 3,400 BTC on September 7. The remaining 598.5 BTC, however, appears to be held as a bounty, and Blockstream has drawn a hard line. On September 11 the company publicly refused to pay for the return of the outstanding coins, framing the demand as theft rather than a legitimate bug-bounty claim.
Not everyone in the ecosystem accepts the white-hat framing. Alena V., a bitcoin developer known online as @AlenaSatoshi, wrote on September 7: "If you exploit vuln, steal 4k BTC and demand a fix for ransom, that's EXTORTION. This can mean felony charges and long prison time. In the U.S. up to 20 years, and computer-fraud charges can add more."
The Lawsuit and the Failed Deal: Legal and Financial Pressure Mounts
While the hack dominated headlines, a separate legal problem emerged in a California courtroom. River Financial filed suit on September 11 against Blockstream Services Canada ULC in the Northern District of California, seeking about $6.7 million over a canceled bitcoin-mining contract. The complaint, filed under diversity jurisdiction with a jury demand, alleges breach of a termination agreement. River says the deal called for $3.55 million in prepaid refunds and a $3.15 million early-termination payment, and that six months of $239,000 repayments were missed.
The defendant's name matters. Blockstream Corp said on September 26 that the U.S. and Canadian services firms have not been under its ownership or management since mid-2024, and that they retained the Blockstream name only under license following an April 2025 spin-out. In other words, the entity in the lawsuit is a former affiliate that kept the brand, not the Blockstream Corp that runs Liquid. Initial social-media headlines flattened the distinction, but the legal record points to Blockstream Services Canada ULC specifically.
The third pressure point is corporate rather than legal. BSTR Holdings (Cayman), led by Back, had planned to become a public bitcoin treasury company through a merger with Cantor Equity Partners I, a special-purpose acquisition company. The deal contemplated a 30,021 BTC treasury and was announced with the expectation of a Nasdaq listing. It never closed. On August 20 the parties terminated the July 16, 2025 business combination agreement, as amended on March 25, 2026, according to an SEC-filed current report.
The termination leaves a $15 million cash obligation with two fixed deadlines: $10 million on or before September 19 and $5 million on or before December 1. Under the executed termination agreement, BSTR Holdings must pay Cantor Equity Partners I, but the contract allows the buyer to request that Blockstream Capital Partners make the payment instead - in which case Blockstream Capital Partners must pay. A delay of more than seven days would automatically void the releases and covenant-not-to-sue provisions granted by the Cantor side, stripping the other parties of legal protections they bargained for.
In an issuer press release filed with the SEC, BSTR pointed to "pricing pressure in Bitcoin markets and among listed Bitcoin treasury vehicles, plus capital-market dislocation" as the context that limited strategies using convertible bonds and perpetual preferred equity - the funding machinery the transaction relied on. The merger, financing, and registration machinery behind the proposed listed vehicle has been unwound, and the parties intend to withdraw the Form S-4 filed for the transaction. BSTR said it would continue bitcoin treasury management outside the abandoned deal, but the termination materials do not show how much bitcoin the continuing business currently holds.
Cyclical Shock or Structural Weakness: What the Hack Says About Federated Infrastructure
Here the analysis turns on a distinction that most coverage has treated lightly. The Liquid Network is a federated sidechain, not the bitcoin base layer. Its security depends on the signers who run Elements software and the multisig arrangement among them - not on bitcoin's proof-of-work consensus, which was never touched during the incident. That is exactly the architecture Blockstream and other sidechain operators have long argued is safer than the bridges and layer-2s built on Ethereum, where the largest thefts of recent years have clustered.
On that measure, this episode is cyclical, not structural. A cyclical shock is one that mean-reverts: the bug is patched, most funds are recovered, the network resumes, and confidence returns because the failure mode was specific and fixable. The evidence for the cyclical read is substantial. The flaw sat in a narrow part of the verification logic tied to peg-outs rather than in Liquid's general transaction processing. The response was fast by crypto-hack standards - the network halted within hours, a patch shipped within days, and 85 percent of the stolen bitcoin came back within roughly 48 hours. Bitcoin traded around $80,000 in the days following the exploit and stood near $84,500 by September 29, a muted reaction for an incident of this size. Traders priced the exploit as a Liquid-specific engineering failure rather than evidence of any weakness in bitcoin itself - precisely the distinction Blockstream has spent years arguing for.
Measured against bitcoin's roughly $1.6 trillion market capitalization at the time, the $320 million taken from Liquid is about 0.02 percent of the network's total value. Small in relative terms, large in absolute terms for a single sidechain event - and, by far, the largest attack recorded against a Bitcoin sidechain.
But the structural counter-argument should not be dismissed. Federated systems concentrate trust in a small set of signers and in the correctness of the software they run. The federation that backs Liquid includes more than 80 exchanges, infrastructure companies and asset managers, and the 11-of-15 multisig approved a payout of bitcoin that had never been locked into the reserve. The vulnerability was not a stolen credential or an outside breach; it was an accounting assumption baked into the validation code - a cache that treated an invalid output as already verified. That is a different class of failure from the "hacked hot wallet" headline, because it means the system behaved exactly as its code allowed, and the code had been reviewed, shipped, and relied upon by institutions.
The unresolved $47 million also matters for the structural read. If the attackers keep it as a self-declared bounty and no regulator or law-enforcement agency brings charges, the episode establishes a precedent: an actor can mint unbacked tokens on a federated chain, redeem them for real assets, return most of the proceeds on their own terms, and retain the remainder as leverage. Blockstream's refusal to pay reframes the retained coins as theft, but it does not recover them. As of September 26, no named regulator, prosecutor, or law-enforcement agency has publicly confirmed an investigation into the incident.
The cleanest reading separates the two time horizons. In the short term, this is a cyclical engineering failure with a fast patch and a high recovery rate - the kind of event that damages a brand but does not break a business model. In the long term, it is a data point against the claim that federated sidechains are categorically safer than the alternatives they compete with. The mechanism that failed was the same mechanism that gives Liquid its value proposition: fast, private settlement backed by a federation rather than by proof-of-work. If the price of that speed is a validation path that can mint value from nothing, competitors building on Ethereum layer-2s will point to it, and institutions that chose Liquid for its safety story will ask harder questions at the next vendor review.
What Comes Next: The Signals That Will Decide the Narrative
Three concrete developments will determine whether Blockstream emerges from September with its reputation intact or with a structural question mark attached to its core product. First, whether the remaining 598.5 BTC is recovered, returned voluntarily, or permanently retained - and whether any law-enforcement action follows. Second, whether Blockstream publishes an independent audit of the Elements codebase and a full accounting that restores L-BTC's one-to-one backing, which exchanges and institutional users will treat as a precondition for resuming normal activity. Third, whether the $15 million BSTR termination payment clears both the September 19 and December 1 deadlines without voiding the Cantor-side releases.
The strongest counter-thesis is that none of this touches Blockstream's fundamentals: the hack hit a federation the company does not solely control, the lawsuit targets a legally separate former affiliate, and the failed SPAC was a financing vehicle rather than an operating business. On that view, September is noise around a company whose core products - Liquid, the Lightning implementations, the satellite network, and its mining and finance arms - remain intact, and whose CEO remains one of bitcoin's most credible technical figures.
That defense holds only if the federation distinction persuades institutional customers. The falsifying signal is specific: if two or more major exchanges that use Liquid for settlement publicly migrate their bitcoin operations to a competing sidechain or layer-2 within the next quarter, or if L-BTC trading volumes fail to recover to pre-incident levels after the network fully resumes, the "separate federation" defense will have failed in the market that matters - the customers' own routing decisions.
For now, the picture is of a company facing simultaneous pressure on three fronts - a security incident that is the largest of its kind in 2026, a lawsuit over a canceled mining contract, and a collapsed public listing that leaves a $15 million obligation on its doorstep. The recoveries, the patch, and the legal separation of the sued entity are real mitigants. But the burden of proof has shifted: Blockstream must now demonstrate that federated infrastructure can be trusted not because it says so, but because its code, its audits, and its customer retention show it.
The sharpest takeaway is also the least comfortable for bitcoin's infrastructure builders: the industry spent years arguing that sidechains were the safe alternative to Ethereum bridges, and the biggest bitcoin-sidechain hack on record arrived through the same category of failure - code that let unbacked tokens become real money.
更多独家洞察尽在 nextfin.ai.
