
Blockstream has refused to pay a ransom for roughly 598.5 BTC that remains under the control of the actors behind the Liquid Network exploit after 3,400 BTC was returned earlier this week.
Summary
- Blockstream has refused to pay a ransom for Bitcoin still held by the actors behind the Liquid Network exploit.
- The actors previously returned 3,400 BTC after nearly 4,000 BTC was withdrawn from Liquid’s federation wallet.
- Blockstream rejected the actors’ white hat position and said taking funds without authorization and withholding their return amounts to theft.
- The company said it will work with law enforcement, exchanges, forensic specialists and service providers to trace and recover the remaining Bitcoin.
Blockstream said in an X post on Sept. 11 that taking assets without authorization and withholding their return amounts to theft, rejecting the actors’ description of their actions as responsible disclosure or white-hat activity.
“We will not pay a ransom for the return of stolen funds,” the company said. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
The statement follows several days of communication between Blockstream and the unidentified actors after nearly 4,000 BTC was withdrawn from Liquid’s federation wallet on Sept. 6.
Blockstream rejects ransom for remaining Bitcoin
Blockstream said it had engaged with the actors in good faith to recover funds belonging to users and protect the Bitcoin community, but said the talks did not amount to acceptance of either the withdrawal or the terms later demanded.
The company argued that developers of open-source Bitcoin software should not be forced to pay a ransom that exceeds their economic participation in a project after someone exploits the code.
“Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom,” Blockstream said.
The dispute centers on approximately 598.5 BTC that remains outstanding following the return of 3,400 BTC to Liquid’s federation wallet on Sept. 7. The repayment recovered roughly 85% of the Bitcoin withdrawn during the incident.
The remaining Bitcoin was worth close to $47 million when the larger repayment was completed. No publicly disclosed agreement had authorized the actors to retain the coins as a bounty.
The actors had initially described themselves as “whitehats” and communicated with Blockstream through messages embedded in Bitcoin transactions. Before returning the 3,400 BTC, they told the company to fix the vulnerability and ensure that every affected node had been patched.
Blockstream later confirmed through a signed message that its bridge nodes had been patched and that the funds were safe to return.
As crypto.news previously reported, the actors had offered to return most of the withdrawn Bitcoin after the vulnerability was fixed, without committing to return the entire amount.
Subsequent on-chain messages changed the terms of the dispute. The actors demanded that Blockstream pay a 10% bounty using its own money or leave Liquid holders facing a loss, according to messages published as negotiations continued.
Blockstream has now rejected any payment tied to the return of the remaining coins.
Liquid exploit left nearly 600 BTC outstanding
The Sept. 6 incident involved a vulnerability affecting Liquid, the Bitcoin sidechain developed by Blockstream. Nearly 4,000 BTC left the federation wallet, representing most of the Bitcoin held in the reserve at the time.
A later examination of the Liquid Network exploit found that the incident stemmed from a cache-key collision in confidential transaction verification logic. Blockstream said federation keys were not compromised.
The actors used the flaw to obtain Bitcoin from the federation reserve before beginning an on-chain exchange with Blockstream. Liquid halted block production during the incident, while exchanges were asked to suspend L-BTC deposits and withdrawals.
After Blockstream patched the affected bridge nodes, the actors transferred 3,400 BTC back to the federation address. Approximately 598.5 BTC remained at an address controlled by the actors.
Blockstream’s latest statement draws a line between its earlier effort to negotiate the return and any agreement to reward the people responsible.
The company said paying the demand would establish a precedent in which open-source developers could be forced to fund large payments after unauthorized withdrawals from systems using their software.
Blockstream told the Bitcoin community that it was continuing to work for users whose funds were taken and thanked engineers, cryptographers and security researchers who had helped identify and patch vulnerabilities across Bitcoin-related software.
The company linked part of the security pressure facing open-source projects to advances in artificial intelligence, saying teams across the Bitcoin ecosystem have been dedicating time to finding and fixing weaknesses in one another’s products and systems.
Security problems involving Bitcoin software have surfaced elsewhere in recent months. In August, BTCPay Server supporters backed a recovery bounty equal to 10% of funds retrieved after an exploit exposed LND admin macaroon credentials. That bounty was capped at 3 BTC if all stolen assets were recovered.
The arrangement followed an active exploit that prompted BTCPay Server to tell operators to install version 2.4.2 or shut down affected servers until they could update.
Blockstream plans to pursue remaining funds
With negotiations failing to produce a complete return, Blockstream said the people controlling the remaining Bitcoin still have an opportunity to send it back and return to what the company called standard white-hat principles.
If the funds remain outstanding, the company said it plans to work with law enforcement agencies, exchanges, service providers, forensic specialists and other parties to trace the Bitcoin and identify those responsible.
Bitcoin transactions leave a public on-chain record, giving investigators a continuing view of movements from addresses associated with the incident even if the coins are later split between multiple wallets.
A similar tracing process has been used following other major Bitcoin thefts. Galaxy Research, for example, found in August that 1,561 BTC remained unmoved after researchers attributed 1,789.28 BTC in losses to the Coldcard exploit. Identified attacker addresses were shared with exchanges, compliance companies and law enforcement.
Blockstream said the transparency of Bitcoin would allow the community and investigators to continue following evidence left by transactions involving the Liquid funds.
“Transactions do not disappear, and neither does the evidence they leave behind,” the company said.
The company maintained that it would neither pay for the return of stolen property nor stop pursuing the outstanding Bitcoin.
“Return the bitcoin,” Blockstream said.








Leave a Reply