Blockstream has publicly refused to pay a ransom for the roughly 598.5 BTC that remains under the control of the actors behind the Liquid Network exploit, rejecting their framing of the incident as white-hat research and pledging to pursue the funds with law enforcement, exchanges and forensic specialists.
“We will not pay a ransom for the return of stolen funds,” the company said in a Sept. 11 post on X. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
The statement follows days of on-chain negotiation after nearly 4,000 BTC was withdrawn from Liquid’s federation wallet on Sept. 6, and after the actors returned 3,400 BTC on Sept. 7 — roughly 85% of the withdrawn amount. The remaining coins were worth close to 47 million USD when that repayment completed.
How the negotiation broke down
The actors had initially described themselves as white hats and communicated with Blockstream through messages embedded in Bitcoin transactions. Before returning the 3,400 BTC, they told the company to fix the vulnerability and ensure every affected node had been patched — conditions Blockstream later confirmed it met through a signed message verifying that its bridge nodes had been updated.
Subsequent on-chain messages changed the terms. The actors demanded that Blockstream pay a 10% bounty from its own funds, or leave Liquid holders facing the loss. Friday’s statement is Blockstream’s formal answer: no payment of any kind tied to the return of the remaining coins.
Blockstream argued that developers of open-source Bitcoin software should not be forced to pay a ransom exceeding their economic participation in a project after someone exploits the code. “Bitcoin is hard money and can’t be minted without costs. Bitcoin doesn’t haircut users to pay a ransom,” the company said.
An expensive cache-key collision
A post-incident examination found the Sept. 6 exploit stemmed from a cache-key collision in confidential transaction verification logic. Federation keys were not compromised; the actors used the flaw to extract Bitcoin directly from the federation reserve, which represented most of the Bitcoin held in the reserve at the time.
Liquid halted block production during the incident, and exchanges were asked to suspend L-BTC deposits and withdrawals. Block production resumed after the affected bridge nodes were patched, with the Elements software updated to harden the range-proof cache keys involved in the bug.
The episode is the largest security event this year for a Bitcoin sidechain, and its resolution has become a test case for how the industry treats partial returns after exploits — a gray zone between negotiated bug bounties and outright extortion.
Precedent worries and the path forward
Blockstream said paying the demand would establish a precedent in which open-source developers could be forced to fund large payouts whenever someone drains a system built on their software — effectively converting public code into an unlimited liability for its maintainers.
The company left the door open for a voluntary return, saying those controlling the remaining Bitcoin still have an opportunity to send it back and return to standard white-hat principles. If the funds stay outstanding, Blockstream said it will work with law enforcement agencies, exchanges, service providers and forensic specialists to trace the coins and identify those responsible.
Bitcoin’s public ledger gives investigators a continuing view of movements from addresses tied to the incident, even if the coins are split across multiple wallets. “Transactions do not disappear, and neither does the evidence they leave behind,” the company said, closing with a two-word demand: “Return the bitcoin.”
A different playbook than BTCPay’s bounty
The stance contrasts with a notable precedent from August, when supporters of BTCPay Server backed a recovery bounty equal to 10% of retrieved funds — capped at 3 BTC — after an exploit exposed LND admin macaroon credentials. That bounty was funded voluntarily by the project’s community rather than demanded by the attackers as a condition of return.
Blockstream also linked the growing security pressure on open-source Bitcoin infrastructure to advances in artificial intelligence, saying teams across the ecosystem have been dedicating time to finding and fixing weaknesses in one another’s systems. The Coldcard exploit trail — where researchers attributed 1,789 BTC in losses and tracked 1,561 BTC sitting unmoved at identified addresses shared with exchanges and law enforcement — illustrates the tracing apparatus now awaiting anyone who holds stolen Bitcoin at scale.
For Liquid users, the immediate crisis has passed: 85% of the taken funds are back, the network is producing blocks, and peg-outs have resumed under tightened procedures. The fate of the final 598.5 BTC now moves from negotiation table to investigation — with Blockstream betting that time and blockchain transparency favor the pursuers, not the holder.
“it is not white hat activity. It is theft.” politely said but absolutely the right call. paying a ransom on 598.5 BTC just guarantees the next exploit
negotiating via messages embedded in bitcoin transactions is honestly the most cyberpunk thing i’ve read all week
@onchain_olaf right? imagine leaving a permanent paper trail of your extortion on a public ledger while claiming to be the good guy
Exactly, op_return notes are immutable marketing for the case against you. Boldest self-own since the Silk Road server.
Returning 3,400 of 4,000 BTC and then keeping 598.5 as a “bounty” after promising white hat behavior. The self-incrimination through OP_RETURN is remarkable.
47M and they think exchanges wont freeze it the second it moves? law enforcement has gotten scary good at this
598.5 BTC sitting in limbo and the exploit actors still think they will get paid lmao. blockstream was never gonna reward a ~4k BTC grab
Refusing the ransom is the only move here. The moment you pay one, every federation becomes a target
agree, but tracing 598 BTC through exchanges is gonna take years. that money is probably being mixed somewhere already
years of tracing plus a permanent on-chain confession letter. every OP_RETURN message is exhibit A for the prosecutors lol
mixing only delays it though. returning 3,400 btc proved they can move size, which means exchanges already have the withdrawal fingerprints on file
returning 3,400 BTC then holding 598.5 hostage for a bounty is the worst negotiation posture ive ever seen. blockstream loses nothing by waiting, the actors lose everything the longer they hold
blockstream waiting costs them nothing while that 47M gets colder by the day. the OP_RETURN negotiation trail was the real unforced error on the actors side
85 percent returned within a day, then they haggle over 598.5 and frame it as a bounty. the sept 11 statement basically dared them to keep it and eat the consequences