Reading view

There are new articles available, click to refresh the page.

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft

Bitcoin Magazine

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft

Bitcoin infrastructure firm Blockstream has refused to negotiate further with hackers who last week stole 4,000 bitcoins from its Liquid network. 

Writing on X Friday, Blockstream said that the hackers still had time to return the funds before the company would work with law enforcement. 

White-hat hackers on Sunday withdrew about $320 million from the federation wallet that backs Liquid, a sidechain by Blockstream. After negotiating with Blockstream, they returned most of the funds but kept 598.5 coins worth over $46 million — demanding it as ransom. 

“Blockstream will not pay a ransom for the return of stolen funds,” the post read. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”

To those responsible for the theft of bitcoin from the Liquid Network:

Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is…

— Blockstream (@Blockstream) September 11, 2026

It added: “We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible.”

“We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”

Liquid, or L-BTC, is a layer-2 created by Blockstream that allows users to fast move assets backed 1:1 with bitcoin. One of the assets, LBTC, is a token backed by bitcoin that allows for quick settlement — a bit like the Lightning Network. 

Hackers were able to get the funds by exploiting an inflation bug on the Liquid sidechain to create over 4,000 LBTC that did not exist before and cash them out for real, on-chain bitcoins. 

The hackers then had an exchange with Blockstream via messages written into Bitcoin blocks. 

In one message, the white hats wrote: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

In the latest message, the hackers slammed Blocksteam as “delusional, greedy, and arrogant,” and threatened to reveal all of Blockstream’s encrypted messages in the exchange unless the company allowed thieves to keep 10% of the bitcoins. 

“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the message read. 

The Bitcoin community is still reeling after hackers in July were able to steal over 1,800 bitcoins worth close to $140 million from Coldcard wallet holders. 

Users of the popular hardware wallet, created by Coinkite, were targeted because the product’s manufacturer did not use a true random number generator, allowing hackers to essentially guess investor seedphrases. 

This post Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Brazil’s cruise missile testing resumes after years of delay

Brazil’s Avibras Aeroco and the Brazilian Army completed a successful test launch of the country’s first indigenous cruise missile on August 26, a milestone in a certification process that stalled for roughly four years while the missile’s manufacturer worked through a severe financial crisis. The test took place at the Army Evaluation Centre’s Marambaia Test […]

Eric Wu’s newest company, out of stealth since May, is going after construction’s labor crunch

Eric Wu, who built and ran Opendoor before stepping away in 2022, has had his new company, NavigateAI, out of stealth since May — building AI copilots that give construction workers real-time, hands-free guidance through smartphones and Meta's AI glasses, backed by $25 million from Elad Gil, Khosla Ventures, and Lennar to tackle a labor shortage severe enough that data center projects alone now need 4,000 to 5,000 workers apiece.

Kraken Files For CFTC-Regulated U.S. Perpetual Futures Product

Kraken parent Payward has filed to launch CFTC-regulated perpetual futures for eligible U.S. traders through Bitnomial, the Designated Contract Market acquired by the company.

The proposed products would cover BTC, ETH, SOL, XRP, and ADA perpetual derivatives, according to Kraken’s announcement. The filing marks an important step because perpetual futures are one of crypto’s most heavily traded instruments globally, but U.S. access has historically been far more constrained.

This does not mean trading is live today.

The launch remains subject to a 30-day regulatory self-certification review process. That is the key caveat.

For more details, visit the official Blog platform.

TL;DR

  • Kraken parent Payward filed for CFTC-regulated U.S. perpetual futures.
  • The products would be listed through Bitnomial.
  • Trading is not live yet and remains subject to regulatory review.

Why Perpetual Futures Matter

Perpetual futures are central to crypto trading.

Unlike traditional futures, they do not expire on a fixed date. Traders use them for leverage, hedging, market-making, directional exposure, and basis strategies. In global crypto markets, perpetuals often dominate derivatives volume.

The U.S. market is different.

Regulated access is more limited, and many crypto perpetual products have operated offshore. A CFTC-regulated product would give eligible U.S. traders a more compliant route into an instrument they already use elsewhere through global platforms.

That makes Kraken’s filing a significant market-structure development.

Bitnomial Is The Regulatory Route

The Bitnomial relationship matters.

Bitnomial is a CFTC-registered Designated Contract Market, which gives Payward a regulated venue framework for derivatives listings. Rather than simply offering offshore-style perps through Kraken directly, the product is being routed through a regulated market structure.

That distinction is important.

It affects who can access the product, how contracts are listed, what rules apply, how surveillance works, and what disclosures traders receive.

BTC And ETH Are The Obvious Starting Point

The inclusion of BTC and ETH makes sense.

They are the deepest and most institutionally accepted crypto assets. But the proposed product suite also includes SOL, XRP, and ADA, which would widen regulated derivatives access beyond the two largest assets.

That could matter for altcoin market structure.

If eligible U.S. traders get regulated perpetual exposure to several large-cap tokens, offshore derivatives markets may face new competition. It could also give institutions a more familiar venue for hedging altcoin exposure.

Review Period Comes First

The market should not jump ahead of the process.

A filing is not the same as a live product. Kraken’s announcement points to a self-certification review period, meaning launch timing depends on the regulatory process and any issues raised during review.

Until that period is complete, traders should treat this as a proposed regulated product.

That is still meaningful, but it is not the same as live trading volume.

The Bigger Signal

Kraken’s move shows U.S. crypto derivatives are still evolving.

The market has long wanted deeper regulated access to products that already dominate global trading. If perpetual futures can be structured inside CFTC-regulated venues, the U.S. derivatives landscape could become more competitive.

The key is whether the product clears review and how widely it is available.

For now, Payward’s filing gives the market a serious signal: regulated U.S. crypto perps are moving from concept toward product reality.

This article draws on Kraken’s announcement relating to CFTC-regulated U.S. perpetual futures through Bitnomial.

This article was written by the News Desk and edited by Samuel Rae.

This report is based on information released by Blog. at Blog

Liquid Network Pauses After Purported $320M White-Hat Bitcoin Withdrawal

Liquid Network paused operations after a purported $320 million Bitcoin withdrawal from multisig reserve addresses, with the party behind the transaction claiming it was a white-hat rescue tied to a suspected security flaw.

The key detail is scope. This was not Bitcoin mainnet stopping. Bitcoin blocks kept moving as normal. The issue concerns Liquid, Blockstream’s Bitcoin sidechain, where operators halted transaction processing while engineers reviewed the incident.

That distinction matters because sidechain security stories can easily sound bigger than they are. A pause on Liquid is serious for users and developers relying on that network, but it does not mean Bitcoin itself failed or stopped producing blocks.

The situation is still sensitive. Until operators publish a full incident report, the safest framing is that the network paused after an unusual withdrawal and a public white-hat claim.

Loading Tweet…

View original post on X

TL;DR

  • Liquid Network paused operations after a purported $320 million Bitcoin withdrawal.
  • The party behind the transaction claimed white-hat rescue intent.
  • Bitcoin mainnet was not affected.
https://x.com/Liquid_Network/status/2064216929443963344

What Happened On Liquid

Liquid is a Bitcoin sidechain designed to support faster settlement, confidential transactions, and asset issuance for exchanges, traders, and institutions.

Because it operates separately from Bitcoin mainnet, it has its own operational structure and security assumptions. Bitcoin locked into Liquid is managed through a federation model rather than Bitcoin’s native proof-of-work settlement.

That is why a suspected multisig issue becomes a major event.

If a large withdrawal occurs from reserve addresses and the party involved claims to be protecting funds from a possible flaw, operators have to take the situation seriously. Pausing the network can be disruptive, but it may be the safer choice while engineers check what happened and whether funds remain secure.

White-Hat Claims Need Care

The white-hat claim is important, but it should not be treated as settled fact without confirmation.

A white-hat actor is someone who identifies or acts on a security issue with the intention of preventing harm rather than stealing funds. In crypto, that line can become messy when funds are moved before a full disclosure process is complete.

The public claim may prove accurate. It may also require further verification.

That is why the wording around the incident matters. The funds should not be described as permanently stolen unless official operators confirm losses. Equally, the incident should not be dismissed as harmless until audits are complete.

Why Liquid Users Care

Liquid users care because sidechains depend on trust in their bridge, operators, and security design.

A pause interrupts normal use. Exchanges, traders, issuers, and wallet users may need to wait for clarity before moving assets or relying on settlement. Even if funds are safe, uncertainty itself can affect confidence.

That is especially true for a Bitcoin-linked network.

Liquid exists partly because users want Bitcoin-based liquidity with extra functionality. If the sidechain faces a major security review, users naturally want to know whether the bridge model is sound.

Not A Bitcoin Mainnet Incident

This point needs to stay front and center.

Bitcoin mainnet did not halt. Bitcoin mining, block production, and ordinary BTC transfers were not affected by the Liquid pause. The incident concerns a federated sidechain connected to Bitcoin, not Bitcoin’s base layer.

That does not make the story unimportant.

It just means the risk is specific. Liquid’s incident may raise questions about sidechain design, multisig security, and federation governance, but it does not show that Bitcoin’s core network stopped working.

What Comes Next

The next update should come from Liquid or Blockstream operators.

Users will want a clear timeline: what triggered the withdrawal, whether the white-hat claim is accepted, whether any funds were at risk, what security issue was suspected, and when normal operations can resume.

A full technical report would matter more than a short status update.

Until then, the market has to treat this as an active sidechain security incident with limited confirmed facts.

Liquid’s pause is a serious operational event. But the bigger lesson is also familiar: Bitcoin-linked systems are only as strong as their own security assumptions, even when Bitcoin itself keeps running.

This article draws on Liquid Network’s official status update and public materials relating to the incident.

This article was written by the News Desk and edited by Samuel Rae.

This report is based on information released by X. at X

Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves

Bitcoin Magazine

Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves

The Liquid Network said Sunday that purported white-hat hackers withdrew about 4,000 bitcoin, worth about $320 million, from the federation wallet that backs L-BTC. Bridge nodes were disabled, and the sidechain was paused. Other issued assets, including USDT, DePix and RWAs, were unaffected, the official account said on X.

The Liquid Network is a federated sidechain of Bitcoin, founded by Adam Back’s Blockstream. The Liquid chain issues a variety of assets such as LBTC, which it backs with BTC on the Bitcoin main chain, held in a large multisig of 15 corporate and known members. 11 of the 15 members need to sign a valid multi-signature transaction to move coins from the treasury. Before the hack, the treasury held over 4200 BTC; after the hack, Blockstream’s proof of reserves page reports a little over 207 BTC left. 

The hackers withdrew 4,019.4 BTC from the reserve address in a peg-out transaction using the SideSwap Peg-out Authorization Key. SideWap is a bridge exchange and a member of the Liquid Federation. While details on the mechanism of the hack are not confirmed yet, it appears an inflation bug on the LBTC side chain was exploited by the hackers to create over 4,000 LBTC that did not exist before, and cash them out for on-chain bitcoin from the federation. Because the transaction appeared as valid, given the consensus bug, the federation members’ HSM security servers signed the BTC withdrawal transaction, worth roughly 320 million at the time. 

The hacker moved the funds to an address ending in 6gyqjlte, from which they quickly signed a new transaction with a message on the OP_RETURN arbitrary data field saying “we are whitehats. contact us on chain.” Those coins were still at that address at the time of writing.

A small mainnet transaction to the hacker address followed by an OP_RETURN saying “Please contact security@blockstream.com”, presumably from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried “Please contact us on Signal @m671aw.70”, however, this may be spam and does not share a link to the address with the stolen funds.

In response to the breach, exchanges were told to pause L-BTC deposits and withdrawals. Bridge nodes on the Liquid Network have been paused, limiting access to the side chain, which continues to produce blocks. 

JAN3 CEO Samson Mow said Aqua’s Liquid features were affected and that on-chain bitcoin still worked. Other wallets in the industry that use the Liquid Network are expected to be affected. Users holding LBTC now effectively have their savings at risk, since the underlying BTC is currently not redeemable. Given the private nature of the Liquid chain, user onchain analytics are scarce and not much public information is known about how much LBTC is held by retail users versus corporations of Blockstream itself. Nevertheless, should the funds not be returned, it would be a heavy blow to the Liquid Network’s user base.

Users of LBTC don’t have many options but to wait for conversations with the hackers to resolve. Given the size of the hack, it would be difficult for the hackers to get away with stealing all that bitcoin, though perhaps not impossible. What may happen is that the hackers ask for a finder’s fee and return the majority of the funds. 

This post Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves first appeared on Bitcoin Magazine and is written by Juan Galt.

CFTC Advisory Sets Expectations For Tokenized Collateral At Clearinghouses

The CFTC’s Division of Clearing and Risk has issued a staff advisory on how registered derivatives clearing organizations should handle tokenized collateral, including tokenized U.S. Treasuries used as margin.

The advisory is a narrow but important signal. It does not approve tokenized collateral for every market. It does not mean all clearinghouses can suddenly accept any on-chain asset. It sets risk-management expectations for registered DCOs dealing with a specific emerging market structure.

That makes the document useful for understanding how regulators are approaching tokenized assets inside core financial plumbing.

For more details, visit the official Cftc platform.

TL;DR

  • The CFTC issued staff guidance for DCOs handling tokenized collateral.
  • The advisory covers risk controls around tokenized U.S. Treasuries used as margin.
  • It is not a broad approval of all tokenized assets across all markets.

Why DCOs Matter

Derivatives clearing organizations sit deep inside financial market infrastructure.

They help manage counterparty risk, margin, settlement, and default processes for derivatives markets. Most retail crypto traders do not think about DCOs, but institutions care about them because clearing determines how risk is controlled after trades are made.

If tokenized collateral enters this part of the market, the stakes are high.

Collateral needs to be valued accurately. It needs to be liquid enough under stress. It needs strong custody arrangements. It needs legal clarity. It needs operational resilience.

The CFTC advisory speaks to those requirements.

Tokenized Treasuries Are Moving Closer To Market Infrastructure

Tokenized U.S. Treasuries have become one of the strongest RWA categories.

They are familiar, relatively liquid, yield-bearing, and easier for institutions to understand than many crypto-native assets. Using them as margin could make sense in some settings, but only if the risks are managed properly.

That is where regulators become cautious.

A tokenized Treasury may represent a traditional asset, but it still introduces digital-asset risks. There can be wallet risk, smart contract risk, transfer restrictions, issuer risk, oracle risk, redemption timing, and technology failure.

A clearinghouse cannot treat the tokenized wrapper as irrelevant.

Liquidity And Valuation Are Central

The advisory highlights the kinds of questions DCOs need to answer.

How is the asset valued daily? What happens if liquidity dries up? Can the collateral be liquidated quickly during stress? Who controls custody? What legal rights does the clearinghouse have? Are there operational dependencies on a blockchain, custodian, or issuer?

Those questions are not theoretical.

Collateral is supposed to protect the system during bad conditions. If tokenized collateral only works during calm markets, it is not good enough for clearing.

Not A Free Pass For RWA

Crypto markets may be tempted to read the advisory as regulatory approval for tokenized assets.

That would be too broad.

The document is about expectations for registered DCOs. It does not bless every RWA protocol, every tokenized fund, or every tokenized Treasury product. It also does not remove the need for clearinghouses to satisfy existing regulations.

The more measured view is that tokenized collateral is now serious enough to require detailed supervisory expectations.

That is still meaningful.

The Institutional Signal

The advisory shows tokenization is moving from concept to infrastructure.

Regulators are no longer only asking whether tokenized assets are interesting. They are asking how they behave inside regulated market systems. That is a much more advanced conversation.

For crypto, that is a sign of maturity.

The next phase of RWA adoption will depend less on splashy launches and more on whether tokenized assets can survive legal, operational, custody, and liquidity scrutiny.

The CFTC’s advisory is part of that test.

This article draws on the CFTC Division of Clearing and Risk staff advisory on tokenized collateral for registered derivatives clearing organizations.

This article was written by the News Desk and edited by Samuel Rae.

This report is based on information released by Cftc. at Cftc

❌