Blockstream Rejects Ransom After Liquid Hack as AI Security Group Claims Prior Warning
A dispute has erupted between Blockstream and the AI-driven Bitcoin Red Team over whether a vulnerability was flagged before the theft of nearly 600 BTC.
Blockstream is refusing to pay a ransom to hackers who stole nearly 600 BTC from the Liquid Network, while a security initiative claims the disaster was preventable. The clash highlights a growing friction between traditional infrastructure providers and new AI-driven auditing groups.
Approximately 598.5 BTC, valued at roughly $47 million, remain missing following the exploit of the Liquid Network. In the wake of the theft, the attackers attempted to negotiate the return of the funds, but Blockstream has officially rejected all ransom demands. The company stated that taking assets without authorization and withholding their return is a crime rather than "white-hat activity," and is not considered responsible disclosure.
The AI Audit Dispute
The controversy centers on the "Bitcoin Red Team," a collaborative security effort involving developer Calle and Rob Hamilton. The group utilizes large language models, specifically Moonshot AI's Kimi K3, to perform rapid security audits of open-source projects within the Bitcoin ecosystem. According to the group, they scanned hundreds of repositories—with reports ranging from 390 to 501—in a short window, identifying thousands of potential vulnerabilities.
The Bitcoin Red Team claims it specifically warned Blockstream about the vulnerability used in the Liquid exploit before the attack occurred. Blockstream, however, disputes the assertion that it ignored these warnings, attributing the security failure instead to a flawed bug fix related to AI.
Implications for Cybersecurity
This incident underscores the escalating "AI arms race" in cybersecurity, where both attackers and defenders employ LLMs to identify and patch software bugs. The dispute suggests a breakdown in the coordinated vulnerability disclosure process, particularly when AI-driven researchers identify risks at a scale and speed that traditional development teams may struggle to verify or integrate.
What's Next
As the funds remain missing, the industry is watching whether this incident will force a standardization of how AI-generated security warnings are handled by major infrastructure providers. It remains unverified whether the Bitcoin Red Team's specific warning was delivered in a format that Blockstream could have acted upon, or if the vulnerability was a direct result of the AI-related fix cited by the company.