Highlights

  • Blockstream publicly refused a 10% ransom demand from the Liquid Network attacker still holding roughly 598 BTC.
  • The attacker threatened a permanent 15% loss for Liquid users if the "bounty" went unpaid.
  • Blockstream says withholding stolen funds for payment isn't whitehat behavior — it's theft.
  • The company is now working with law enforcement and forensic specialists to trace the remaining Bitcoin.
  • The standoff is the latest chapter in a saga that began with a $320 million bridge exploit on September 6.

Blockstream said on September 11 that it will not pay a ransom to the hacker still holding roughly 598 BTC, worth close to $47 million, stolen in a September 6 exploit of its Liquid Network Bitcoin sidechain. The attacker, who has cast the intrusion as security research, had demanded Blockstream hand over 10% of the original haul from the company's own treasury, warning that refusal would leave Liquid's users absorbing a permanent 15% loss. Blockstream's response, posted on X, drew a sharp line between legitimate vulnerability disclosure and what it called outright theft, and confirmed it is now working with law enforcement, exchanges and forensic investigators to track the outstanding funds and identify whoever is responsible.

How the Standoff Escalated

The exploit itself unfolded on September 6, when an attacker used a vulnerability in Liquid's federation bridge nodes to withdraw close to 4,000 BTC, worth roughly $320 million at the time, forcing Blockstream to halt block production while it patched the flaw.

Within days the attacker returned 3,400 BTC once the fix was confirmed, but kept back approximately 598.5 BTC — worth about $47 million — and framed the retained coins as a self-assigned "bounty" for exposing the weakness. That framing has been treated skeptically from the start, much as the original "whitehat" claim was doubted when the breach first surfaced: a genuine white hat typically returns everything and negotiates compensation afterward rather than unilaterally keeping a nine-figure sum. The attacker's subsequent demand escalated the dispute further, asking for an additional 10% of the original withdrawal — paid out of Blockstream's own funds, not the recovered Bitcoin — and pairing the request with a threat that Liquid's user base would otherwise be stuck with a lasting 15% shortfall. Cointelegraph reported that Blockstream's refusal was unambiguous, with the company stating that withholding assets obtained without authorization in exchange for payment does not constitute legitimate security research.

Why the Refusal Matters Beyond One Sidechain

Related: Liquid Network Hacker Escalates, Demands 10% Bounty From Blockstream's Own Funds

The standoff matters beyond one sidechain's balance sheet because Liquid sits at the center of Bitcoin's institutional plumbing — exchanges, market makers and OTC desks use it to settle BTC and issued assets faster and more privately than the base layer allows. A federation-bridge exploit that isn't fully resolved leaves a lingering question over how robust that settlement layer really is, and Blockstream's public refusal to pay is as much a signal to the wider industry as it is a response to one attacker. Paying a ransom, even dressed up as a "bounty," would set a template other attackers could copy: breach a bridge, return most of the funds, then negotiate a cut of the rest as if it were a bug-bounty payout rather than extortion. By instead committing publicly to law-enforcement and forensic tracing, Blockstream is betting that recovery through investigation is more sustainable than incentivizing future exploiters to follow the same playbook. For now, the 598 BTC remains outside Blockstream's control, an unresolved liability sitting alongside Liquid's other operational fallout from the breach. Whether that Bitcoin is ever recovered will likely shape how exchanges and institutions weigh Liquid's risk profile going forward, and could influence how other Bitcoin sidechains and bridges design their own incident-response and bounty policies in the wake of this dispute.

What to Watch Next

The immediate question is whether law enforcement and the forensic specialists Blockstream says it's now working with can actually trace and freeze the outstanding 598 BTC before it moves through mixers or into harder-to-trace channels — a race that typically narrows within days of a public refusal like this one. Watch for whether the attacker responds to Blockstream's rejection with a further escalation, a partial return, or silence, any of which would signal how serious the "bounty" framing ever was. Liquid's own transaction processing, only partially restored since the September 6 incident, is the other marker worth tracking: full resumption without further incident would help rebuild institutional confidence in the sidechain faster than the ransom dispute itself gets resolved.

FAQ

What is Blockstream's Liquid Network?
Liquid is a Bitcoin sidechain built by Blockstream that lets exchanges and institutions settle BTC and other assets faster and more privately than Bitcoin's base layer, using a federation of bridge nodes rather than Bitcoin's own consensus.

How much Bitcoin is still missing after the Liquid Network exploit?
About 598 BTC, worth close to $47 million, remains outstanding after the attacker returned 3,400 of the roughly 4,000 BTC taken in the September 6 breach.

Did Blockstream pay the hacker's ransom demand?
No. Blockstream publicly refused on September 11 to pay the 10% bounty the attacker demanded from the company's own funds, calling the retention of stolen assets for payment illegitimate.

What happens next in the Liquid Network case?
Blockstream says it is working with law enforcement, exchanges and forensic investigators to trace the remaining Bitcoin and identify those responsible, though no recovery timeline has been given.