Blockstream Refuses Ransom for 598.5 Bitcoin (BTC) From Liquid Network Exploit
Blockstream rejected a ransom demand for 598.5 BTC left from the Liquid Network exploit, calling the theft a crime, and will pursue legal avenues to recover…
AI SummaryAI
- Blockstream refused to pay a ransom for roughly 598.5 BTC held by the Liquid Network attackers.
- Attackers minted about 4,000 unbacked L-BTC and drained nearly 4,000 BTC, roughly 95% of federation reserves.
- Roughly 3,400 BTC, about 85% of the stolen funds, was returned to the federation on Sept. 7.
- Blockstream released Elements v23.3.4 and Liquid block production has resumed normal processing.
Blockstream Refuses Ransom Demand
Blockstream has drawn a hard line against the group behind the Liquid Network breach, declaring that it will not pay a ransom for the roughly 598.5 Bitcoin (BTC) still held by the attackers. In a statement posted on Sept. 11, the firm rejected the group’s characterization of the heist as responsible disclosure, arguing that taking assets without authorization and withholding their return is a crime — not white-hat activity. The company said it had engaged with those responsible in good faith in an effort to recover user funds, while insisting the talks never constituted acceptance of the withdrawal or of the terms later demanded. Rewarding the holdout, Blockstream argued, would create a damaging precedent in which developers of open-source software could be forced into ransoms far exceeding their economic participation in a project. “Bitcoin is hard money,” the firm wrote, describing the original proof-of-work asset as something that cannot be minted without cost and does not haircut users to cover a ransom. The dispute centers on a cache of roughly 598.5 BTC — worth close to $47 million when the bulk repayment was completed — that never came back after the majority of the stolen funds were returned earlier this week. No publicly disclosed agreement ever authorized the attackers to retain the coins as a bounty. Every L-BTC token in circulation is designed to act as a wrapped Bitcoin claim, redeemable one-for-one against reserves held by the Liquid Federation, which is why unbacked issuance cuts directly at the sidechain’s trust model. Blockstream left the door open for a responsible resolution but warned it will pursue every available legal avenue if the remaining coins are not returned, noting that Bitcoin’s public ledger preserves every movement — transactions do not disappear, and neither does the evidence they leave behind.
How the Liquid Exploit Unfolded
The incident dates to Sept. 6, when attackers abused a vulnerability in Liquid, Blockstream’s federated sidechain used for rapid settlement and Bitcoin DeFi activity. On-chain analysis shows the group minted roughly 4,000 L-BTC without the BTC collateral supposed to back those tokens, then pushed the counterfeit claims through SideSwap’s peg-out infrastructure and extracted nearly 4,000 real BTC from federation reserves. The federation wallet held about 4,200 BTC at the time — roughly $320 million — meaning the drain removed about 95% of the backing in a single sequence. A subsequent post-mortem traced the root cause to a cache-key collision in the confidential transaction verification logic; federation keys themselves were not compromised. Liquid halted block production during the incident, and exchanges were asked to suspend L-BTC deposits and withdrawals. After Blockstream shipped Elements v23.3.4 to patch the flaw and confirmed via a signed message that bridge nodes were safe, the actors sent 3,400 BTC back to the federation address on Sept. 7, recovering about 85% of the stolen sum. The remainder stayed at an attacker-controlled address. The group, which initially posed as whitehats communicating through messages embedded in transactions, told the firm to fix the vulnerability across every affected node before escalating its terms: pay a 10% bounty from Blockstream’s own money or leave Liquid holders facing a loss. Former Blockstream chief strategy officer Samson Mow, who has provided regular recovery updates, said Liquid transactions are processing normally again, though L-BTC remains only about 85% backed while the outstanding coins are unreturned. The episode also lands amid broader security strain on open-source tooling: in August, BTCPay Server supporters backed a recovery bounty capped at 3 BTC after an exploit exposed LND admin macaroon credentials, and researchers attributed 1,789.28 BTC in losses to the Coldcard exploit, with 1,561 BTC still unmoved.
On-Chain Trail in Focus
Our read of the record: transparency gives investigators leverage, but not a guarantee. The attacker transactions remain permanently auditable, and the post-mortem — a cache-key collision, remediated in Elements v23.3.4 with federation keys untouched — provides forensic specialists a verified baseline for tracing splits across wallets. Yet identified addresses alone have rarely forced quick returns elsewhere. In COINOTAG’s view, refusing the ransom protects open-source developers from a costly precedent, and with roughly 598.5 BTC still traceable, pressure on the holdout group is structural, supported by the week’s most closely watched Bitcoin security case.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


