Blockstream Rejects Ransom Demand After Recovering 85% of BTC Stolen in Liquid Network Exploit

AI Market Summary
Blockstream recovered ~3,400 of 4,000 BTC stolen via a Liquid Network Elements logic bug that enabled unbacked LBTC to be swapped for real BTC, and refuses to pay for the remaining 598.5 BTC. While keys and multisig custody were not compromised, the exploit highlights smart/validation risk in Bitcoin-adjacent infrastructure and may pressure confidence and liquidity in Liquid and related BTC settlement flows amid ongoing law-enforcement recovery efforts.
Impact level
● High
Affected assets
BTC/USDT+0.53%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Blockstream said it will not pay a ransom for the remaining Bitcoin missing from last week's Liquid Network exploit, after recovering the bulk of the funds. The company reported it has retrieved about 3,400 BTC of the roughly 4,000 BTC drained from a Liquid Network federation wallet on Sept. 6. In an update issued Sept. 11, Blockstream said it will not compensate the attackers to recover the outstanding 598.5 BTC, valued at about $47 million. Blockstream argued that paying for the return of stolen assets amounts to negotiating with thieves, not responsible security disclosure. It warned that meeting such demands would establish a repeatable template for future attacks across the industry. The incident stemmed from a software bug in the Elements codebase, the open-source framework that underpins Blockstream's Liquid sidechain. According to the company, the flaw enabled the creation of unbacked LBTC, Liquid's pegged asset, which was then swapped for real BTC held in the federation wallet. Blockstream said the federation's signing keys were not compromised and that Liquid's multisignature custody model remained intact. Instead, the attackers exploited a logic issue in how the network validated peg transactions. Patches were deployed quickly, and by Sept. 7 roughly 3,400 BTC had been returned, representing about 85% of the stolen funds. Liquid temporarily paused operations during the recovery effort, then resumed with an updated block production schedule. Communications between Blockstream and the perpetrators played out publicly via on-chain OP_RETURN messages and PGP-signed Bitcoin transactions. The attackers initially presented themselves as white hats and demanded a 10% bounty in exchange for returning all funds. After Blockstream did not comply, they threatened that BTC holders would face a 15% loss unless their terms were met. Blockstream rejected the white-hat characterization, calling the incident theft. The company said responsible researchers disclose vulnerabilities and coordinate with affected teams, rather than draining funds and negotiating afterward. Blockstream added that it has engaged law enforcement and forensic specialists to pursue recovery of the remaining BTC through legal channels. At roughly $47 million, the unpaid ransom would have been one of the year's larger single exploit-related demands in crypto. Liquid Network, launched in 2018, is a federated Bitcoin sidechain built for faster settlement and confidential transactions, used primarily by exchanges and institutional traders. Its model relies on a consortium of functionaries that jointly manage the peg between Bitcoin and LBTC.