"Most of the developers who worked on Liquid and introduced the initial bug, or missed it, have long since moved on..." I think it's worth noting here that apparently it wasn't the 'initial' bug that was exploited; but a buggy fix to that recently discovered 'initial' bug. Regardless, it is absolutely Blockstream's responsibility for critical bugs not to continue to be missed regardless of the turnover of their developers. That said, despite the obviously deserved hit to Blockstream's reputation, I agree they shouldn't be paying any ransom. BTW, this was a theft from Blocksteam's users in the same way a bank robbery is a theft from the banks' account holders (i.e. it isn't). If a bank ends up with no choice but to rug those clients due to resulting issues of insolvency; then, those clients just happened to trust the wrong bank. *none of this is intended to imply that Blockstream should never be used for anything again in the future... just stay informed of the risks; and proceed accordingly with caution. *also worth noting that the federated model of custody was revealed to completely breaks down to mere theater when each member uncritically relies on the same code to direct them on which transactions to authorize.