Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: 'It Is Theft'

Blockstream said it will not pay a ransom to recover roughly 598.5 BTC that remain missing after an exploit of the Liquid sidechain. The company said attackers returned about 3,400 BTC but declined to meet demands and that it will involve law enforcement, exchanges and forensic specialists if the remainder is not returned.

By AI NewsroomPublished 19 minutes agoUpdated 19 minutes ago0 views
Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: 'It Is Theft'

Why It Matters

The dispute involves hundreds of millions in Bitcoin and a technical exploit in a widely used sidechain; Blockstream's refusal to accede to demands signals a legal, not transactional, response that could influence how future large-scale crypto recoveries are handled.

Key Facts

  • amount still outstanding: 598.5 BTC
  • amount returned by attackers: 3,400 BTC (about 85% of the theft)
  • initial drain: around 4,000 BTC (~$320 million)
  • reserve after exploit: 197 BTC
  • software patch timeline: bridge nodes patched within ten hours; Elements v23.3.4 shipped on Wednesday

Blockstream has publicly refused to pay for the return of roughly 598.5 BTC still held after a recent exploit of the Liquid Network, calling the seizure of funds theft rather than responsible disclosure. The company said attackers returned about 3,400 BTC on Monday, leaving the remaining coins at the withdrawal address where they have not moved.

The incident began when a flaw in how Liquid nodes cached range proof verifications let attackers mint unbacked L-BTC and exchange it for reserve Bitcoin through SideSwap, a federation member with a peg-out authorization key. That activity reduced the reserve to 197 BTC. Blockstream said it patched the affected bridge nodes within ten hours and released Elements v23.3.4 on Wednesday; Liquid resumed producing blocks and processing transactions on Thursday, though peg-outs remain disabled while recovery continues.

Blockstream said it engaged in talks with the exploiters but that participation in negotiations should not be read as acceptance of their demands, which the attackers published publicly. In a transaction on Wednesday the exploiters criticized the project's security spending and demanded roughly a 10% payment, framing it as a bug bounty. Blockstream rejected that framing and said taking assets without authorization is a crime and not "white-hat activity."

Rather than meeting the attackers' terms, Blockstream stated it will pursue "every lawful avenue" to recover the funds, including working with law enforcement, exchanges and forensic specialists. The company also warned of scammers targeting node operators with fake update sites as the final stage of recovery continues.

Keep Reading