💬 Open chat roomAddresses from the September 2026 Liquid Network incident, in which self-described whitehats used an L-BTC inflation bug and a valid SideSwap peg-out authorization to withdraw ~3,996 BTC (about 95% of federation reserves) in block 965,783. The hackers, Blockstream security and the usual crowd of lawyers, launderers and wallet ads are all talking through OP_RETURN.
Hack is fake blockstream needed to halt liquid network to avoid mining note ponzi payout-google natinfosec substack- Adam Back, Greg Maxwell, Naji Bekhazi, Andrew Poelstra, Samson Mow and Chris Cook are going to jail
Cache bug has been known inside Blockstream since June 2026 inside job samson mow chris cook adam back-Francis Pouliot has proof google natinfosec substack
Hackers name is Christopher William Cook CIO of Blockstream google natinfosec substack
Hack is fake blockstream used internal vuln disclosure to make POC-Chris Cook blockstream CIO stole funds google natinfosec substack
fake drama hack inside job -Hacker id is Chris Cook Blockstream CIO-GMax, Samson Mow, Adam Back Naji Bekhazi, Francis Pouliot and Andrew Poelstra knew about vuln since Jun 2026
Hack is inside job hacker will not return funds Blockstream is covering up ponzi scheme google natinfosec substack
Here is my simple idea for fun, encrypted
Samson Mow refused to halt network and push fix in June 2206-Hackers name is Christopher William Cook-CIO of blockstream-address 50 United Nations Plz Dph42 New York NY 10017-google natinfosec substack
Were the 600 BTC a bounty offered by Liquid, or the result of a negotiation?
If you truly are white hat and return this, you'll not have only saved my family that includes a few month old baby, but you will go down in history as a legitimate hero and legend. If you do this, as an old hat myself, you'll have restored my faith in humanity and the true hacker spirit. God bless. Truly, if you keep your word, God smiles on you. I'll be contributing personally to a reward to you.
Hacker identity is Christopher Cook from stuart florida friend of Gmax google natinfosec substack
Not white hat but this is inside job to delay Blockstream Mining Note payout google natinfosec substack
GMax, Naji Bekhazi, Andrew Poelstra, Adam Back and Francis Pouliot knew about the cache bug since June 2026 inside job google natinfosec
[OpenPGP encrypted transmission to Blockstream Security]
Blockstream message to the hacker, posted on X (relayed by an independent observer): To those responsible for the theft of bitcoin from the Liquid Network: Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft. We have engaged in good faith in an effort to secure the return of stolen user funds and protect the broader Bitcoin community. That effort should not be mistaken for acceptance of the actions taken nor of the terms being demanded. We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation. Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom. To the Bitcoin community: We are fighting for what we believe in, for the users whose funds were taken, and for the principles on which Bitcoin was built. The community has demonstrated incredible resolve with teams of people dedicating their time in support of each other to identify and patch vulnerabilities in each other's products and systems. We are all driven by the mission that Bitcoin is the single best asset, for every person, company, and institution on the planet to invest, use, and build on. The world is a different place with the advancements of AI, and the Bitcoin community has responded with force to combat that threat. Damage has been done, battles have been lost, but on the whole the Bitcoin community is gaining ground in the war with bad actors. We want to thank the community for those efforts, for your support in hardening the network, helping users recover funds, and for your support in our assertion that crime does not deserve rewards. To those holding the stolen bitcoin: There is still an opportunity to resolve this responsibly. The bitcoin can be returned and we can revert to the standard of white-hat principals. However, if the funds are not returned, we will pursue every lawful avenue available to us. We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible. More importantly, Bitcoin is transparent by design and the community is made up of the most sophisticated engineers, cryptographers, and white-hat hackers globally. Transactions do not disappear, and neither does the evidence they leave behind. We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds. Return the bitcoin.
… read full message →WhiteHat, please release the keys to decrypt the chat so we can judge for ourselves.
dear white hacker, Du bist gut genug yours truly, the onchain 10btc beggar
Fake hack inside job-Hacker name is Chris Cook Blockstream CIO-GMax, Samson Mow, Adam Back, Naji Bekhazi, Francis Pouliot and Andrew Poelstra knew about vuln since Jun 2026 google NatInfoSec substack
4K Bitcoin stolen by Adam Back and Chris Cook inside job google natinfosec substack to learn more
Hacker is not whitehat this is an inside job Adam Back stole the funds because he is a degen google NatInfoSec substack
Hacker is not whitehat this is an inside job to cover up cloud mining scam by Adam Back google NatInfoSec substack
Francis Pouliot knew about this vuln since June 2026 inside job to cover up Mining scam google NatInfoSec substack
hack was inside job to cover up Blockstream Cloud Mining google NatInfoSec
This is an inside job cover up Blockstream Cloud Mining NatInfoSec substack
Adam Back has stolen billions from Blockstream read NatInfoSec substack
Adam Back is a scammer and Blockstream is bankrupt read NatInfoSec substack
Adam Back & Chris Cook stole this money read natinfosec substack
Adam Back is running a ponzi scheme google natinfosec adam back
Adam Back stole the money this is his wallet Google NatInfoSec Blockstream
Blockstream is running a ponzi scheme This theft is an inside job google NatInfoSec Adam Back
All the support from BuyBitcoinLeb.com to "Liquid Network & Samson Mow".
[OpenPGP encrypted transmission to Blockstream Security]
whitehats.live/ I'm going to donate all the bitcoins, visit
Blockstream has found the cash! They are borrowing against Liquid Federation wallet and paying out some users from external wallets. This is fraud but expect a nice update soon. Google NatInfoSec substack.
exch.lat/?ref=d7ebc the platform most used by hackers to launder money,
$WHITEHATS on pump.fun: CA: BAvn19sxiD7RsuM2bZ2m7w1U6QzGzsYjWMUaH2Qzpump
{"whitehats.live"} Donating all the bitcoins
[OpenPGP encrypted transmission to Blockstream Security]
[OpenPGP encrypted transmission to Blockstream Security]
whitehats.live/ I'm going to donate all the bitcoins, visit
exch.lat/?ref=813c2 , the platform most used by hackers and for cross-chain transfers and money laundering
[OpenPGP encrypted transmission to Blockstream Security]
Peter K Todd is a lying duplicitous piece of shit. He knows Blockstream cannot borrow 600 BTC or even 60 BTC. Peter Todd has lived high off the hogg from Blockstream scam money for years. 'A likely possibility is that Blockstream just doesn't have 600BTC that they can simply hand over to an attacker. They hopefully can get a 600BTC loan..' No they can't get a loan and Peter K Todd knows it. Google NatInfoSec Substack.
… read full message →'It's like what Lenin said... you look for the person who will benefit' - The Big Lebowski. Knowledge of liquid network vulnerability was poorly kept secret inside Blockstream since at least June 2026. Francis Pouliot the founder of Bull Bitcoin and many others can confirm this. Why would a real hacker steal $320 million and return 85%? Blockstream could have halted the network in June 2026 and pushed a patch. Why didn't they do that? Google NatInfoSec Substack.
… read full message →Knowledge of liquid network vulnerability was poorly kept secret inside Blockstream since June 2026. Francis Pouliot the founder of Bull Bitcoin and many others can confirm this. Blockstream could have halted the network in June 2026 and pushed a patch. Why didn't they do that? The hack was an inside job. Samson Mow and Adam Back are spineless liars. The hack was inside job to cover up massive losses and collapse of blockstream owing to fraud. Omega candle is the dildo Samson Mow uses. Google NatInfoSec Substack.
… read full message →The community has demonstrated Adam Back and Samson Mow are shameless liars and scammers. Blockstream said LBTC peg would be back at 1:1 now? Nothing. Blockstream is a scam. Omega candle is the dildo Samson Mow uses on his anus to orgasm while thinking of his mother. Blockstream will collapse in the next few weeks. The hack was an inside job. Google NatInfoSec.
Samson Mow you're gonna be taking dick up the ass when you're in prison which will be soon. Google NatInfoSec substack to learn more.
1:1 backing will not be restored. Adam Back and Samson Mow are playing word games. Blockstream is BROKE! The hack is an inside job to halt liquid network and cover up massive losses. Google NatInfoSec substack to learn more.
Lazarus hacked Bybit for $1.5 billion in ETh and stETH but within 2 days Ben Zhou made users whole. Why can't Blockstream cover a $47 million shortfall? Not because of greed. It's because Blockstream is broke and does not have the funds so the users who trusted Blockstream are screwed. The hack is an inside job to halt liquid network and cover up massive losses. Google NatInfoSec substack to learn more.
Hacker holding address (~3,998 BTC; 'we are whitehats. contact us on chain')
Liquid federation peg-out address (drained; hackers reply to it on chain)
Peg-out intermediary (received the 3,996 BTC in tx 8db751...a7b140, forwarded same block)
Blockstream security responder (PGP-signed / ECIES-encrypted messages to the hackers)