Full-Time
Bitcoin infrastructure provider: networks, wallets, mining
No salary listed
Menlo Park, CA, USA
Hybrid
Two to three days per week in the Menlo Park office required.
See people who can refer or advise you
Blockstream provides infrastructure for Bitcoin and digital assets, including the Liquid Network, Core Lightning, wallets (Green and Jade), Blockstream Satellite, and mining services. Liquid is a sidechain that enables faster, more private settlements; Core Lightning is a scalable Lightning Network implementation for quick Bitcoin payments; wallets store Bitcoin and Liquid assets; Satellite broadcasts the blockchain from space to give global access; Mining services offer investment exposure via Blockstream Mining Notes. It differentiates itself by offering multiple interconnected infrastructure products in one place, plus notable partnerships like solar-powered mining facilities, serving both retail and institutional clients. Its goal is to improve the security, scalability, and reach of the Bitcoin and digital asset ecosystem with practical, interoperable tools for users, traders, miners, and developers.
Company Size
51-200
Company Stage
N/A
Total Funding
$637.1M
Headquarters
Menlo Park, California
Founded
2014
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Flexible Work Hours
Remote Work Options
Stock Options
401(k) Retirement Plan
Performance Bonus
Blockstream bets 600 Bitcoin by rejecting Liquid hacker's $50 million bounty demand. The fight over the remaining $46 million is splitting crypto over whether rewarding partial restitution encourages cooperation or invites extortion. Senior Reporter - CryptoSlate Sep. 12, 2026 Quick take. * 01 Blockstream rejected the Liquid attacker's demand for nearly 600 BTC after 3,400 BTC was returned following the September exploit. * 02 The dispute pits deterrence against restitution, as paying could reward attacks while refusing may reduce incentives for future hackers to cooperate. * 03 Liquid remains about 85% reserve-backed, with peg-ins and peg-outs disabled while Blockstream traces the remaining funds or fills the gap. Blockstream is refusing to pay the Liquid attacker nearly 600 Bitcoin (roughly $50 million), escalating a dispute over how the crypto industry should reward partial restitution. The standoff follows an unusual recovery from the Sept. 6 exploit, when a vulnerability allowed the attacker to create about 4,000 unbacked L-BTC and withdraw roughly 3,996 real BTC through SideSwap. The attacker returned 3,400 BTC after Blockstream patched affected nodes, then demanded a 10% bounty paid from Blockstream's own funds and warned that holders could otherwise bear a roughly 15% shortfall. On Sept. 11, Blockstream rejected the demand and said it would pursue the remaining funds through law enforcement, exchanges, service providers, and forensic specialists if they are not voluntarily returned. The decision has opened a broader argument over whether refusing to compensate an attacker who returned about 85% of the haul strengthens deterrence or gives the next hacker less reason to return anything. Blockstream's rare recovery turns into a fight over incentives. The return of 3,400 BTC shifted the fight from recovering stolen funds to defining what cooperation after an exploit is worth. Lorenzo Romagnoli, co-founder of USDT0, said Blockstream had already received an outcome that most hacked crypto protocols could only hope for. He argued that an attacker linked to North Korea or another committed criminal group would have little incentive to voluntarily send back hundreds of millions of dollars. Romagnoli said: "Blockstream is already in the 1% of the 1% of luckiest hacked protocols on the planet." He said Blockstream retains every right to identify and prosecute the attacker, but warned that refusing a substantial bounty could change future hackers' calculations. A grey-hat attacker weighing whether to return stolen funds may see little upside in cooperation if restitution brings the same pursuit as keeping the entire haul. That argument collides with Blockstream's concern that paying would create a different incentive: allowing an attacker to exploit open-source infrastructure, seize user assets and then establish the price for returning them. Blockstream said it would not establish a precedent in which developers of open-source software could be forced to pay a demand that "far exceeds their economic participation." It also rejected the attacker's white-hat characterization and urged the party to "return the Bitcoin." Samson Mow, a former Blockstream chief strategy officer and chief executive of Bitcoin company Jan3, also challenged the economics behind the attacker's demand. The attacker had criticized Blockstream for allegedly spending too little to protect roughly $5 billion in assets issued across Liquid. Mow said that figure combines L-BTC, Tether, and real-world assets that belong to different issuers and holders, making the network's total asset value an inappropriate basis for determining a bounty. "Bounty amounts cannot be calculated based on the network's overall total value. Regardless of how the rest is negotiated, all users' assets must be returned in full." The circumstances preceding the withdrawal have also complicated the attacker's white-hat claim. SideSwap said the party spent hours rehearsing the transaction pattern before creating the unbacked L-BTC, with 70 similar transactions preceding the successful mint. The wallet used to initiate the attack had received funding that traced through a cross-chain bridge to Tornado Cash. In view of this, SideSwap called the event a "deliberate and prepared attack," while adding that: "We stand with Blockstream. The bitcoin left the Liquid reserve through our peg-out service and we have given Blockstream everything we have to help trace and recover it. Our fee on it is already returned. Return the Bitcoin." The last 600 BTC may be more useful unspent. With the bounty rejected, the remaining 598.5 BTC can continue putting pressure on Liquid even if the coins never move. Bitcoin researcher Alex Waltz questioned whether the attacker genuinely expects to spend the coins. According to him, the wallet is closely watched, and moving the BTC through exchanges, custodians, or other identifiable services could provide investigators with additional leads. That creates another possible motive for keeping the funds. Waltz said the attacker effectively faced two choices after returning most of the haul: return everything and hope Blockstream provides a generous reward, or retain a portion that may be difficult to spend but can continue inflicting an economic cost on Liquid. "If the hackers are somewhat well off, and had a good reason to hate Blockstream/Liquid, it seems the only way they can 'monetize' this situation is to keep the 600 BTC." He also raised the possibility that investigators could eventually obtain clues from artificial intelligence services used by the attacker if models were accessed through identifiable API accounts, though no evidence has emerged publicly showing that such services were used. The economic pressure is already visible on Liquid. SideSwap said on Sept. 10 that 4,205 L-BTC remained in circulation while the federation reserve held 3,597 BTC, leaving about 85% reserve coverage after the returned bitcoin was added back. Liquid has resumed producing blocks and SideSwap markets have reopened, but peg-ins and peg-outs remain disabled while the federation completes its security review. Blockstream Chief Executive Adam Back said the L-BTC-to-BTC peg will ultimately be covered one-for-one and urged holders not to sell at a discount. Blockstream has yet to detail how it will finance the roughly 600-BTC gap if the attacker refuses to return the funds, or when it will resume full redemptions. Meanwhile, SideSwap has said it will keep its peg service offline until the federation introduces a new security architecture and will disclose the changes before reopening it. Blockstream's alternative path now depends on tracing the remaining BTC and identifying whoever controls it. Until either the coins return or the reserve hole is filled from elsewhere, Liquid's markets can trade again while its core promise of converting L-BTC back into Bitcoin remains suspended. Market Signal Bullish 68 / 100 $77,355.57 0.46% 1H 0.05% 24H 0.46% 7D 2.83% 30D 21.67% 60D 23.24% 90D 19.87% Market cap $1.55T Volume (24h) $30.86B 4.45% Circ. supply 20.08M FDV $1.62T
Crypto hack: Blockstream rejects ransom as nearly 600 Bitcoin remains missing. CryptoWorld September 11, 2026 Crypto News 3 minutes read Blockstream has refused to pay for the return of Bitcoin after a theft from the Liquid Network because it believes that security researchers should not steal! Most of the funds have already been returned, but nearly 600 BTC, which is worth about $47 million, remains with the people behind the attack. How the Liquid Network hack unfolded. The incident began when attackers found a flaw in software used by Liquid, a Bitcoin-based network designed to support faster transfers and other financial services. Through the weakness, around 4,000 Liquid Bitcoins were generated, which were then exchanged for the real Bitcoin on the network. They [the attackers] described what they did as "white-hat" activity, and about 3,400 BTC was returned afterwards. But Blockstream said that the negotiation it had before with the people behind it was just to get users' funds back, and that it should not be interpreted as accepting their actions or demands. Blockstream draws a line over the remaining bitcoin. In a public statement, Blockstream declared that it would not be paying a ransom to recover the remaining funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft. Blockstream said they were not going to pay, stating that paying would create a bad precedent for those who develop open-source software. Instead, it promised to aid law enforcement, exchanges, and BTC blockchain investigators to find the BTC that had not yet been seized and trace those responsible for the attacks. Blockstream ended the statement with a direct demand: "Return the bitcoin." Bitcoin community questions Blockstream's position. The refusal has divided some members of the Bitcoin community. Whale Coin Talk wondered if the situation could have been worse still and pointed out that the funds were returned, so it was an actual white hat, as another group might never have given them back. Seems like white-hat hackers are doing a better job than protocols at keeping users safe. Others focused on Blockstream's responsibility for the vulnerability. Kurt Wuckert Jr. summarized that criticism by writing: Code is law when it benefits CryptoWorld, but law is law when its code gets people robbed. All these do not answer the questions of whether the attackers are security researchers, and show why the case became more than a crypto hack. It also raises the issue of when unauthorized testing can be called extortion. Final summary. * Blockstream says it will not pay for the return of nearly 600 BTC still held by the attackers. * The partial return of approximately 3,400 BTC has caused disagreement over whether the incident involved white-hat research or theft.
SlowMist: Liquid Network cache-key collision bug led to 3,998.5 unbacked LBTC mint. AI Market Summary SlowMist attributes the Liquid Network incident to a consensus-layer rangeproof cache collision in Elements, enabling ~3,998.5 unbacked LBTC to bypass verification and be redeemed for mainnet BTC. Although ~3,400 BTC was returned, ~598.5 BTC remains with the attacker and peg operations are suspended during recovery. The episode heightens counterparty and bridge/federation risk perceptions around Bitcoin-adjacent infrastructure. Impact level Affected assets BTC/USDT +0.65% AI Insight · BTC/USDT AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly. SlowMist said the September 6 incident on Blockstream's Liquid Network stemmed from a consensus-layer weakness tied to a rangeproof verification cache collision in the Elements codebase. The firm estimates roughly 3,998.5 LBTC entered circulation without any corresponding Bitcoin pegin, then was quickly consolidated and redeemed via the federated pegout process for real BTC on the Bitcoin mainnet. According to SlowMist's reconstruction, the attack did not require stolen signing keys or a compromised pegout authorization key. Instead, it used a sequence of structured transactions. Two preparatory transactions placed range proofs and commitments on-chain while priming node caches with crafted data. A subsequent transaction reused a colliding cache key with different field boundaries. When nodes registered a cache hit, they skipped cryptographic verification and minimum-value checks, allowing a counterfeit commitment to be accepted. SlowMist attributed the root cause to cache-key construction that concatenated variable-length fields without length prefixes, making it possible for different input sets to hash to the same key. The issue affected Elements versions prior to 23.3.4, including builds released after an August 3 patch that added missing fields but did not properly protect field boundaries. Elements 23.3.4, released September 8, introduced length prefixes and added an emergency option to disable the rangeproof cache entirely. SlowMist said the update closes the specific collision pathway that turned a performance optimization dating back to 2016 into a consensus-level vulnerability. Liquid restarted block production in a controlled manner on September 10, initially without user transactions, as federation members updated nodes and continued monitoring before gradually restoring service. The financial fallout remains unsettled. Roughly 3,400 BTC was returned to the federated peg wallet the next day, while 598.5 BTC remained under the attacker's control at the time of SlowMist's publication. SlowMist said the attacker continued moving funds and embedded messages demanding a 10% bounty. Pegin and pegout operations remain suspended. Blockstream has rejected the bounty demand, and Adam Back said the peg will be fully covered, leaving the timing of reserve replenishment as the main outstanding question.
Liquid restarts block production after $320M exploit; transactions still frozen. The Main Takeaways * Liquid Network has resumed block production but user transactions remain frozen and peg operations are disabled. * An exploit allowed the creation of unbacked LBTC, leading to a loss of approximately 4,000 BTC. * Liquid's recovery plan involves replaying valid transactions before restoring peg operations, with no timeline announced yet. Liquid Network has restarted block production four days after an exploit drained roughly 4,000 BTC from the Bitcoin sidechain's federation wallet, but the restart stops short of restoring normal service. User transactions remain frozen, while peg-ins and peg-outs are still disabled as operators monitor the network and rebuild the BTC backing for LBTC. Exploit created unbacked LBTC. The incident stemmed from a flaw in Elements, the open-source software underlying Liquid, that allowed roughly 4,000 LBTC to be created without corresponding Bitcoin reserves. Liquid's incident updates said the unbacked tokens were accepted as valid before being sent through SideSwap's authorized peg-out service, prompting the federation to release approximately 4,000 BTC. No federation or SideSwap private keys were compromised. Before the incident, Liquid said its reserve contained about 4,205 BTC. The balance fell to 197 BTC after the malicious withdrawal and other peg-outs processed before the network was stopped. The actors responsible, who described themselves as white-hat security researchers, later returned 3,400 BTC. About 598.5 BTC remains outstanding, leaving restoration of the full BTC/LBTC reserve as one of the main unresolved steps before peg operations can resume. Emergency patch brings blocks back online. Blockstream released Elements v23.3.4 on September 9 to address the vulnerability. The update hardens the cache keys used when verifying range proofs, the area Liquid identified as the source of the validation failure. Liquid said the required functionary and bridge-node updates have now been deployed and functionaries are signing and validating blocks normally. Blocks are deliberately being produced without transactions while operators confirm the network has stabilized. The recovery plan calls for valid transactions to be replayed before peg operations are restored. Liquid has not announced when transactions or peg-ins and peg-outs will reopen, and the remaining 598.5 BTC has not yet been returned. Mandy Williams is a full-time cryptocurrency reporter. Having entered the blockchain space in early 2017, she leverages a diverse background in multi-niche writing and content strategy to cover the evolving digital asset market. Mandy is dedicated to breaking down complex Web3 concepts and spreading mainstream awareness of blockchain technology.
Liquid 'white-hat' group escalates dispute with Blockstream, seeks 10% bounty over alleged security lapses. AI Market Summary Escalating claims of serious security failures around Blockstream's Liquid sidechain and an ongoing extortion-like bounty demand keep the network paused and disrupt pegin activity. Although most of the ~4,000 BTC removed from the Federation wallet was returned, residual funds remain with the attackers and threats to publish sensitive material heighten operational and reputational risk. The episode reinforces counterparty and bridge risk concerns for BTC-linked sidechain usage. Impact level Affected assets BTC/USDT -1.93% AI Insight · BTC/USDT AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly. Tensions between Blockstream and a group claiming to be white-hat hackers have intensified, according to a new update from Samson Mow. The group alleges "serious security failures" at Blockstream and claims the company set aside only $1.5 million - or possibly nothing - to safeguard roughly $5 billion in assets. In a message aimed at Blockstream, the hackers described the situation as "flagrant neglect of security" and demanded a 10% bug bounty paid from Blockstream's own funds. They warned that nonpayment could translate into losses of up to 15% for Liquid users. The note also labeled Blockstream "delusional, greedy, and arrogant" in its approach to security, and said the group intends to publish the private key required to decrypt its conversations after the fact. Liquid remains paused while Blockstream and federation members work through additional security remediation, address a chain split, and plan a coordinated restart. Users have been instructed not to send Bitcoin to Liquid pegin addresses until the network resumes operations. The latest salvo follows the September 6 incident in which about 4,000 BTC - valued near $320 million at the time - was moved out of Liquid's federation wallet. The entity behind the withdrawal initially framed the action as a white-hat intervention, saying the funds would be returned after Blockstream fixed the security issue and patched affected nodes. After Blockstream said the bridge nodes had been patched, 3,400 BTC was returned to the federation wallet, while roughly 598 BTC remained in the hackers' possession. In a separate post, Mow warned the group it may be underestimating the consequences. He said Blockstream's choice to communicate via PGP was a "courtesy" and questioned the wisdom of publicly acknowledging the BTC removal while demanding a bounty. The former Blockstream chief strategy officer added that the group may have left more identifying traces than it realizes, and cautioned that returning funds would not necessarily allow those involved to simply move on. "As a white hat, the road only widens; as a black hat, you're forever on edge. Dreaming of walking away with assets unscathed is nothing but delusion. Some doors, once opened, can never be closed again."