Skip to content
Signal21

Newsletter

Never miss a signal

Get every new signal the moment it lands: the three-horizon Bitcoin read and company coverage, straight to your inbox. One email per update, no noise. Unsubscribe anytime.

One step left

Now confirm it from your inbox

We sent a confirmation email to your address. Click the button inside it and you’re in, without that click, nothing is subscribed.

Not seeing it? Check your spam folder: early deliveries sometimes land there. Marking it “not spam” makes sure you get the signals.

Markets2026-09-10

Liquid hack: the full on-chain conversation between the hacker and Blockstream, message by message

Signal21 Editorial Desk

On September 6, about 4,000 BTC, worth roughly $320 million, left the wallet that backs the Liquid Network, Blockstream's Bitcoin sidechain, through a bug in the Elements software rather than a stolen key. Our outlook of the same day tells that story. This page is about what happened next, and where: the person or group holding the coins and Blockstream talked to each other on the Bitcoin blockchain itself, in messages written into transactions, and the whole exchange is public. Below you will find how such a conversation works, what was said in summary, and then every attributed message in order, with a link to the transaction that carries it.

How a conversation lives inside Bitcoin transactions

Bitcoin transactions can carry a small piece of arbitrary data in an output type called OP_RETURN. The exploiter used it as a mailbox: each message is a transaction that spends a little of the stolen coins, sends 1,000 satoshis to the other side as a carrier, and writes the text into an OP_RETURN output. Blockstream answered the same way, first from a contact address and then from fresh addresses. Some messages are plain text. Some are signed with Blockstream's published security key, so anyone can check they really come from the company. Many are encrypted: the exploiter's notes to Blockstream are encrypted to the company's public PGP key, and Blockstream's notes to the exploiter are encrypted to the key behind the exploiter's own Bitcoin address, using the ECIES scheme built into Electrum wallets. Encrypted messages exist on the chain for everyone to see, but only the intended reader can open them. We show them as encrypted and describe their size; we cannot read them, and neither can anyone else, unless the exploiter publishes the private key as they have threatened to do.

Attribution follows two rules that anyone can verify. A message is the exploiter's when the transaction spends coins from the address holding the stolen funds: the coins are the microphone. A message is Blockstream's when it spends from the company's contact address, or when its text is a PGP clearsigned message whose signature verifies against the key published at blockstream.com, fingerprint 1176 542D A98E 71E1 3372 2EF7 4AC8 CC88 6844 A2D6. Our verified chronology matches the independent audit published by Bitcoin Core contributor Sjors Provoost.

What is not in this thread

A publicly discussed Bitcoin address attracts noise. Since September 6 the exploiter's address has received close to 300 other transactions carrying text: advertisements for memecoins, appeals for a share of the coins, accusations that name individuals and present the theft as an inside job, and at least one message claiming to be from Blockstream's chief executive. None of them spends the stolen coins and none carries a valid Blockstream signature, so none of them is part of the conversation, and we do not reproduce them.

The discussion in summary

First contact, September 6. Four hours after the drain, the address holding the coins wrote "we are whitehats. contact us on chain". Blockstream replied within the hour with its security email address. The exploiter never used it; everything that followed stayed on the chain.

The terms, early September 7. Blockstream sent its first encrypted note. The exploiter then proposed, in plain text, to send "most" of the coins back to Liquid's federation wallet and asked whether that was acceptable. Minutes later it added a condition: fix the bug first, make sure every node is patched, and only then would the money move safely. The technical detail of the flaw followed, encrypted to Blockstream's key. Blockstream answered with a signed "Yes, thank you."

Patched, and paid back. At 09:41 UTC Blockstream posted a signed message: the bridge nodes were patched and the funds were safe to return. The exploiter asked for one more confirmation of the destination address, sent further encrypted detail on the fix, and at 16:09 UTC a single transaction moved 3,400 BTC to the peg wallet. The remaining 598.5 BTC, about 15 percent, stayed at the exploiter's address.

Behind closed doors, September 7 to 8. From that evening the exchange went dark: Blockstream sent a run of signed, encrypted notes, including a short instruction on how to decrypt them, and the exploiter replied in kind. The one readable line from the exploiter in this phase is a sad face, posted late on September 7.

Plaintext, and an ultimatum, September 8 to 9. On the afternoon of September 8 the exploiter announced that all further messages would be in plaintext. On September 9 came the longest message of the thread: an accusation that Blockstream allocated far too little to security, a demand that the company pay 10 percent from its own money as a bug bounty, a threat that its users would otherwise bear a 15 percent loss, and a promise to publish the private key that would unlock the encrypted conversation. Blockstream replied the same hour, encrypted and signed, and again early on September 10. It has not, on the chain or elsewhere, accepted the bounty framing.

The full conversation

Times are UTC. "Exploiter" is the address holding the drained coins; the white-hat label is its own. "Blockstream" marks messages spent from the company's contact address or verified against its published key. Text in quotation marks is reproduced exactly as written on the chain.

Sep 6, 18:30 UTC, block 965,818, Exploiter: "we are whitehats. contact us on chain" (transaction)

Sep 6, 19:31 UTC, block 965,822, Blockstream: "Please contact security@blockstream.com" (transaction)

Sep 7, 01:49 UTC, block 965,865, Blockstream: "Encrypted to the key behind bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte (Electrum BIE1 ECIES):" followed by an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,297 bytes). Not readable by third parties. (transaction)

Sep 7, 02:20 UTC, block 965,869, Exploiter: "sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok" (transaction)

Sep 7, 03:30 UTC, block 965,875, Exploiter: "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix. The detail is as follows (encrypted using https://blockstream.com/pgp.txt)." followed by an encrypted section for Blockstream, not readable by third parties. (transaction)

Sep 7, 03:30 UTC, block 965,875, Blockstream: "Yes, thank you." (PGP-signed, verified) (transaction)

Sep 7, 09:41 UTC, block 965,912, Blockstream: "Bridge nodes are patched, safe to return the funds." (PGP-signed, verified) (transaction)

Sep 7, 12:43 UTC, block 965,930, Exploiter: "plz confirm again that we are sending the coins back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr More details about the vuln fix:" followed by an encrypted section for Blockstream, not readable by third parties. (transaction)

Sep 7, 15:31 UTC, block 965,948, Exploiter: Encrypted message to Blockstream (PGP, 979 bytes). Not readable by third parties. (transaction)

Sep 7, 16:09 UTC, block 965,950, Exploiter: Sent 3,400 BTC to Liquid peg wallet, no message attached. (transaction)

Sep 7, 17:54 UTC, block 965,956, Blockstream: "To decrypt: this is Electrum BIE1 ECIES to your key. In Electrum, Tools > Encrypt/Decrypt Message, paste below, decrypt with the private key for bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. Or any ECIES/BIE1 library." followed by an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,408 bytes). Not readable by third parties. (transaction)

Sep 7, 17:54 UTC, block 965,956, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,275 bytes). Not readable by third parties. (transaction)

Sep 7, 17:54 UTC, block 965,956, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,211 bytes). Not readable by third parties. (transaction)

Sep 7, 17:54 UTC, block 965,956, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,147 bytes). Not readable by third parties. (transaction)

Sep 7, 18:35 UTC, block 965,962, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,275 bytes). Not readable by third parties. (transaction)

Sep 7, 18:35 UTC, block 965,962, Exploiter: Encrypted message to Blockstream (PGP, 962 bytes). Not readable by third parties. (transaction)

Sep 7, 18:35 UTC, block 965,962, Exploiter: Encrypted message to Blockstream (PGP, 1,052 bytes). Not readable by third parties. (transaction)

Sep 7, 21:03 UTC, block 965,973, Exploiter: ":(" (transaction)

Sep 8, 00:11 UTC, block 965,992, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 1,120 bytes). Not readable by third parties. (transaction)

Sep 8, 06:02 UTC, block 966,023, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 3,168 bytes). Not readable by third parties. (transaction)

Sep 8, 09:41 UTC, block 966,052, Exploiter: Encrypted message to Blockstream (PGP, 2,019 bytes). Not readable by third parties. (transaction)

Sep 8, 12:59 UTC, block 966,079, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 4,230 bytes). Not readable by third parties. (transaction)

Sep 8, 14:25 UTC, block 966,087, Exploiter: Encrypted message to Blockstream (PGP, 1,356 bytes). Not readable by third parties. (transaction)

Sep 8, 14:25 UTC, block 966,087, Exploiter: "All messages will be in plaintext." (transaction)

Sep 9, 11:45 UTC, block 966,199, Exploiter: "Your dereliction of duty is obvious that you allocated only $1.5M (maybe even 0) to secure $5B assets. This is a flagrant neglect of security and a sign of complete mismanagement. You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess. Even companies that participate in bug bounty programs cannot guarantee complete security, let alone one like yours that remains delusional, greedy, and arrogant to this very day. Anyway we are going to publish the privatekey to decrypt our conversations afterwards." (transaction)

Sep 9, 11:45 UTC, block 966,199, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 2,222 bytes). Not readable by third parties. (transaction)

Sep 10, 02:18 UTC, block 966,296, Blockstream: an encrypted message to the exploiter (ECIES, PGP-signed by Blockstream, 4,889 bytes). Not readable by third parties. (transaction)

Read it yourself

Every entry above links to its transaction on mempool.space, where the OP_RETURN output can be decoded from the raw script. The live version of this thread runs on our front page, updated as new blocks confirm, and the block-lookup page explains how the attribution is done and what is deliberately left out. Encrypted messages are shown as encrypted there too. If the exploiter publishes the promised key, the closed part of this conversation will become readable, and we will update this page.

This is general market commentary, not investment advice or a recommendation to buy or sell any asset.

  • A new plaintext message from either side, in particular any statement by Blockstream on the demanded bounty of 10 percent.
  • Movement of the 598.5 BTC still held at the exploiter's address, in any direction.
  • Publication of the private key the exploiter promised, which would make the encrypted messages readable to everyone.

All Markets reads