Skip to main content

Cryptocurrency basics

Blockstream Rejects a $50 Million Bounty Demand: What a Sidechain Actually Secures

A reported exploit on Bitcoin's Liquid sidechain puts roughly 600 BTC in question. Here is how sidechains and their trust models work.

7 min read12 September 2026CryptoBipto editorial

Blockstream Rejects a $50 Million Bounty Demand: What a Sidechain Actually Secures

Roughly 600 bitcoin. That is the figure circulating in reports about a security incident on the Liquid Network, a sidechain built alongside Bitcoin by the company Blockstream. According to reporting from CryptoSlate, an attacker who found and exploited a vulnerability demanded a $50 million "bounty" in exchange for disclosing it, and Blockstream declined to pay.

As of this writing the situation is unresolved. The precise nature of the bug, how far the exploit went, and whether any funds are recoverable have not been laid out in full public detail. Treat every specific number as provisional.

You can read our summary of the story here: Blockstream rejects hacker's $50 million bounty demand over Liquid Network exploit. The original report is at CryptoSlate.

The headline is dramatic. The lesson underneath it is durable, and it is the part worth your time: when you move coins onto a secondary network, you are no longer protected by the security of the network you started on. You are protected by whatever that second system does instead. Understanding the difference is one of the more useful things a newcomer can learn, and it applies far beyond this one incident.

First, define the terms

Base layer. The main blockchain itself — in this case Bitcoin. Thousands of independent computers each keep a copy of the ledger and check every transaction against the same rules. No single company can change the record. If you want a refresher on how those computers coordinate, see our lesson on network architecture, nodes, clients, and sync.

Sidechain. A separate blockchain that runs in parallel to the base layer and is connected to it by a mechanism that lets assets move back and forth. A sidechain has its own blocks, its own validators, and — critically — its own rules and its own security assumptions.

Peg. The bridge mechanism between the two. Moving coins from Bitcoin to the sidechain is a "peg-in." Moving them back is a "peg-out."

Federation. A defined group of independent participants who jointly operate something. On Liquid, these participants are called functionaries. They collectively hold the keys to the bitcoin that has been pegged in, and they collectively produce the sidechain's blocks.

Liquid's stated purpose is speed and confidentiality: faster settlement between exchanges and trading desks, and transaction amounts that are hidden from public view using a technique called Confidential Transactions. Those are real features. They come from design choices that also change the trust model.

How a federated peg actually works

Here is the mechanical version, simplified.

  1. You send bitcoin to a special address on the Bitcoin blockchain. Those coins do not disappear. They sit there, locked, controlled by the federation's keys.
  2. After a waiting period of many confirmations, an equivalent amount of a sidechain asset — often called L-BTC — is issued to you on Liquid.
  3. You transact on Liquid. Blocks arrive quickly and predictably because a known set of functionaries is producing them, not an open competition of miners.
  4. When you want out, you burn the L-BTC and ask the federation to release the original bitcoin from the locked address.

Notice what is doing the work in steps 1 and 4. It is not proof-of-work. It is not thousands of anonymous nodes enforcing consensus. It is a defined group of entities holding keys and following software.

That is not an accusation. It is a design trade-off, and Blockstream has described it openly since Liquid launched. Federations can be fast and private precisely because they do not have to convince a global, permissionless network of anything. But the property you get — "a supermajority of named functionaries will behave correctly, and their software will not have a flaw" — is a fundamentally different promise from "the Bitcoin base layer's rules held."

The one-sentence version of the lesson

Every bridge, sidechain, rollup, and wrapped asset replaces the security of the original chain with the security of something smaller. Your job as a user is to know what that something is.

This is why incidents like this one keep happening across the industry and across very different architectures. The base chain is rarely the thing that breaks. The connective tissue is.

When you evaluate any secondary network, these are the questions that matter more than the marketing:

  • Who can move the pooled funds? A federation? A multisignature wallet? A smart contract? A single company?
  • What is the threshold? If eight of eleven signers are required, then eight colluding or compromised signers is your worst case.
  • What happens if the operators go offline? Many federated systems include timelocked emergency recovery paths — a fallback that unlocks after a period of inactivity. Those fallbacks are a safety feature and also an attack surface, because they have their own key holders and their own assumptions.
  • Is the code open and reviewed? Open source does not equal safe. It means flaws are findable by defenders as well as attackers.
  • Who bears the loss if something goes wrong? In most cases, there is no deposit insurance and no legal obligation to make users whole.

These questions are not unique to Bitcoin sidechains. They apply to the app chains and parachains discussed in our lesson on Polkadot, Avalanche, and other major networks, and to any system where a token on one network represents an asset held somewhere else.

Bounty, or ransom?

The word "bounty" is doing heavy lifting in this story, and it is worth separating two very different things.

A bug bounty is a program a company runs in advance. It publishes scope, rules, and payout tiers. A researcher finds a flaw, reports it privately, does not touch user funds, and gets paid. This is a healthy and well-established practice.

What is described in this incident is something else: a flaw was reportedly exploited first, funds were reportedly put at risk, and a payment was demanded afterward. When the money is already moved and the demand comes with leverage attached, security professionals generally call that extortion, regardless of the vocabulary used in the negotiation.

That framing explains why an organization might refuse. The argument for paying is straightforward: it may be the fastest path to recovering funds, and the alternative may be a total loss. The argument against is equally straightforward:

  • Paying establishes a price. It tells every future attacker what a successful exploit is worth.
  • There is no enforceable guarantee. An attacker who has already broken the rules is not bound by a settlement.
  • Payments to anonymous parties can carry legal and sanctions exposure depending on jurisdiction.
  • The disclosed vulnerability might not be the only one, and payment does not buy silence.

Both positions are defensible. Reasonable security teams disagree. What is not in dispute is that the decision is being made under time pressure, with incomplete information, and with other people's money on the line. That is the uncomfortable part.

What this does not mean

A few clarifications, because headlines compress badly.

This is not a flaw in Bitcoin. A vulnerability in a sidechain's software or peg does not affect the base layer's ledger, its rules, or coins that never left it. The two systems are separate by design.

"600 BTC at risk" is not the same as "600 BTC stolen." Reported exposure figures during an active incident often change as facts firm up. Sometimes funds are frozen, recovered, or never actually reachable.

Refusing to pay is not the same as having no plan. Organizations in this position typically pursue several tracks at once: patching, blockchain analysis to trace movement, coordination with exchanges, and law enforcement. None of that is usually discussed publicly while it is happening.

Nobody should read this as a signal about any asset's value. We do not forecast prices and we are not telling you what to do with anything you hold. The point here is comprehension, not a trade.

The practical takeaway

If you use any layer, bridge, or wrapped asset, write down two sentences for yourself: what exactly do I hold, and who has to behave correctly for me to get it back. If you cannot answer the second one, you do not yet know what your risk is.

That exercise scales. It works for a sidechain, for a token that claims to represent a physical resource in a token-incentivized physical network, for a stablecoin, and for an exchange balance. The specific technology changes. The question does not.

One more habit worth building: during a live incident, resist the urge to form conclusions in the first 48 hours. Early reports are frequently revised. Attackers sometimes exaggerate. Companies sometimes understate. The version of this story that turns out to be accurate may not be the version anyone is repeating today.

We will update our news coverage of this incident as confirmed details emerge.

This article is educational and is not financial, legal, or security advice. CryptoBipto does not custody funds or execute trades.

CryptoBipto — editorial standards

Start at the level that suits you and learn at your own pace.