Search
HOME
AUTHOR
ABOUT US
Logo
LOGIN
SIGN UP
arrow-down-right
Logo
  • Home
  • Posts
  • Who Read Blockstream's Code First?

Who Read Blockstream's Code First?

The attacker kept 598.5 BTC and offered a deal. Blockstream called it a crime and chose law enforcement over negotiation.

calendar-blank

Sep 14, 2026

clock

3 min read

On September 1, a code commit appeared in Blockstream's public repository, its title naming the exact bug it fixed. Five days later, an attacker used that bug to bleed Liquid Network's federation wallet like a reservoir with the valve left open. Blockstream did not get out-engineered. It forgot to ship its own fix.

How does a $5 billion settlement layer drain in an afternoon? Start here.

Elon Musk's Insane Projection: 7,692,207%

Where should you invest $100 right now?

Elon Musk just invented and patented this new AI technology…

And he's predicting it will launch a NEW industry that will grow more than 7 million percent in the coming years.

Even if he's only 10% right, that would still be enough to grow $100 into more than $700,000.

Click here to see the details on what Elon Musk called "an infinite money glitch."

The 23-Minute Drain

Liquid is a Bitcoin sidechain where institutions settle trades faster than the main chain allows. Instead of miners, a federation of dozens of companies secures it. Users deposit real BTC and receive L-BTC, a token supposed to be backed coin for coin.

The attacker found a flaw in the code that validates whether coins are real. The software accepted fabricated tokens as genuine, handing back stamped receipts for coins that never existed. In 23 minutes, those fakes converted into $320 million in real Bitcoin and walked out the front door.

Read the Commit, Not the Tweet

The retail narrative settled fast: sophisticated hack, funds mostly returned, crisis contained. The data says otherwise. The bug had been caught, fixed, and merged into Blockstream's open-source codebase. It sat there, published and readable, for the full five days before the attack. The standard move for a fix this dangerous is to ship the patch quietly before publishing the code.

Blockstream skipped that step. Security firm CodeAnt traced the attacker's method back to the public commit itself. The attacker did not need to discover the bug. Blockstream showed it to them. The pipeline from fix to production had run dry long before anyone pulled the trigger.

A $5 Billion Pitch

Here is how Blockstream CEO Adam Back and his team marketed Liquid: Bitcoin's institutional plumbing. The federation listed names like Bitfinex, one of the largest crypto exchanges, and CoinShares, a European digital asset manager, among its members. Tokenized bonds, stablecoins, Treasury bills all flowed through it.

The pitch landed. Roughly $5 billion in assets sat in the system when the attacker struck. Institutions across continents had staked their settlement infrastructure on Back's network. But the engineering underneath that pitch could not hold the weight.

Why Billionaires Are Stockpiling This "Boring" Token

The world's largest financial institutions are building massive positions in a protocol most retail investors consider too "unsexy" to notice. As markets are volatile with recent whale sell-offs, this coin continues setting transaction records while flying almost completely under the radar.

Discover the "boring" financial token that's making the elite wealthy for only $3

15 Pairs of Hands

Only 15 of those federation members actually run the servers that validate every transaction. Picture a skyscraper packed with tenants, but only 15 bolts holding the frame together. Whoever writes the validation code controls the money. Bitcoin Core contributor Michael Folkson called it "security theater." He had reason.

The codebase those servers ran had gone about two years without an update, according to Lopp. The federation's breadth was cosmetic. Its security was concentrated in a handful of machines running stale software.

The Standoff and the Norm It Breaks

The attacker returned most of the stolen Bitcoin. Not all of it. 598.5 BTC, roughly $47 million, stayed in the attacker's wallet like a toll collected at the exit. The demand followed a script written after the Nomad bridge hack in August 2022, when Nomad lost its reserves and publicly offered attackers a share of the haul for returning the rest. That deal hardened into an industry norm.

Every major post-exploit negotiation since has copied some version of it. Blockstream refused. "A crime, not responsible disclosure," the company said. It chose law enforcement over negotiation. Our read: that is a bet on legal recovery with no guaranteed timeline, while $47 million in Bitcoin sits frozen like evidence in a lockbox nobody can open.

One Man's Word

The attacker left a message burned into the Bitcoin blockchain: we are whitehats. contact us on chain. That ratio belongs taped to every federation member's monitor. Back responded on X. The L-BTC peg "will be covered," he wrote. Do not panic sell over the counter.

He named no timeline. He published no reserve proof. He described no mechanism. The bridge that converts L-BTC back to real Bitcoin remains frozen. Blocks resume, but empty. No withdrawals. Galoy CEO Nicolas Burtey wrote that regardless of whether the funds come back, "they've killed Liquid."

What We Watch

The test is simple. Peg-outs must reopen with a published reserve that matches every L-BTC in circulation. Until that happens, L-BTC is a claim on a paused bridge, not a working Bitcoin equivalent. Every exchange and asset manager on the federation must now decide whether a system whose 15 servers ran unpatched code for years still meets their settlement-layer standard.

The commit is still in the repository, timestamped September 1. The bridge is still frozen. The promise is still unaudited. A finished patch that never shipped, and a $5 billion layer running on one man's word.

Crypto Compass holds no position in L-BTC or Blockstream equity.

Stay sharp,
The Crypto Compass

More From Crypto Compass

Who Gave a Chatbot Your Crypto Keys?

Who Gave a Chatbot Your Crypto Keys?

Agents now move 40% of daily crypto volume, and 26.1% of their tools carry a known hole. Ledger's fix: propose, don't approve.

Sep 21, 2026

•

3 min read

Jayson Derrick
Jayson Derrick
Is Solana Staking Worth Five Cents?

Is Solana Staking Worth Five Cents?

BSOL crossed $1 billion in inflows without 1940 Act protections. The ticker looks familiar; the plumbing underneath is thinner.

Sep 20, 2026

•

4 min read

Jayson Derrick
Jayson Derrick
$951 Bought Control of a DeFi Vault

$951 Bought Control of a DeFi Vault

Less than one full governance token stood between depositors and the drain. Read the turnout before you read the audit.

Sep 19, 2026

•

3 min read

Jayson Derrick
Jayson Derrick

Subscribe To Our Newsletter

home

|

author

|

about us

|

Terms of Use

|

privacy policy

by Media Miami LLC
1712 Pioneer Avenue, Suite 500
Cheyenne, Wyoming 82001, United States

© 2026 Crypto Compass. All rights reserved.

Subscribe To Our Newsletter

home

author

about us

Terms of Use

Privacy policy


by Media Miami LLC
1712 Pioneer Avenue, Suite 500
Cheyenne, Wyoming 82001, United States

© 2026 Crypto Compass. All rights reserved.