Blockstream Rejects Ransom Demand After Liquid Network Exploit Leaves $47 Million in Bitcoin Unreturned
The flaw lay in a cache‑key collision within the confidential‑transaction verification logic that the network’s bridge nodes use. Although the federation keys themselves were never compromised, the vulnerability let attackers mint L‑BTC without the corresponding Bitcoin backing.
After the loss was discovered, Blockstream halted block production and asked exchanges to suspend L‑BTC deposits and withdrawals. The company patched the affected bridge nodes on the same day and began negotiating with the actors who had withdrawn the funds.
On September 7, the attackers returned 3,400 BTC—roughly 85 % of the stolen amount—to the federation wallet. Their return was signed by a message that confirmed the bridge nodes had been patched and that the coins were safe to return.
However, the actors kept 598.5 BTC, worth about $47 million at the time of the return. They had been communicating with Blockstream through messages embedded in Bitcoin transactions, describing themselves as “white‑hats.” After the partial return, the actors demanded a 10 % bounty, or 400 BTC, or else threatened a 15 % loss for Liquid holders.
Blockstream publicly rejected the ransom demand. In an X post on September 11, the company stated:
> “Taking assets without authorization and withholding their return is theft, not responsible disclosure. We will not pay a ransom for the return of stolen funds.”
The statement emphasized that Blockstream’s refusal was not a refusal to recover the coins but a refusal to pay a bounty that would set a precedent for future incidents. The company warned that paying would force open‑source developers to fund large payments after unauthorized withdrawals from systems that use their software.
Blockstream said it would continue to work with law enforcement, exchanges, forensic specialists, and service providers to trace the remaining 598.5 BTC. Because Bitcoin transactions are publicly recorded, investigators can follow the movement of the coins even if they are later split across multiple wallets.
The incident remains the largest publicly reported cryptocurrency theft of 2026. While the return of 3,400 BTC restored most of the balance, the remaining 598.5 BTC remains unreturned.
Blockstream thanked engineers, cryptographers, and security researchers who helped identify and patch the vulnerability, and noted that advances in artificial intelligence are increasing the pressure on open‑source projects to find and fix weaknesses.
In summary, Blockstream has refused to pay the ransom demanded by the actors who stole Bitcoin from Liquid’s federation wallet. The company has recovered 3,400 BTC but is still pursuing the remaining 598.5 BTC through forensic tracing and cooperation with law enforcement. The dispute highlights the challenges of securing sidechains and the importance of clear protocols for handling unauthorized withdrawals.