Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: 'It Is Theft'
Blockstream said it will not pay a ransom to recover roughly 598.5 BTC that remain missing after an exploit of the Liquid sidechain. The company said attackers returned about 3,400 BTC but declined to meet demands and that it will involve law enforcement, exchanges and forensic specialists if the remainder is not returned.

Why It Matters
The dispute involves hundreds of millions in Bitcoin and a technical exploit in a widely used sidechain; Blockstream's refusal to accede to demands signals a legal, not transactional, response that could influence how future large-scale crypto recoveries are handled.
Key Facts
- amount still outstanding: 598.5 BTC
- amount returned by attackers: 3,400 BTC (about 85% of the theft)
- initial drain: around 4,000 BTC (~$320 million)
- reserve after exploit: 197 BTC
- software patch timeline: bridge nodes patched within ten hours; Elements v23.3.4 shipped on Wednesday
Blockstream has publicly refused to pay for the return of roughly 598.5 BTC still held after a recent exploit of the Liquid Network, calling the seizure of funds theft rather than responsible disclosure. The company said attackers returned about 3,400 BTC on Monday, leaving the remaining coins at the withdrawal address where they have not moved.
The incident began when a flaw in how Liquid nodes cached range proof verifications let attackers mint unbacked L-BTC and exchange it for reserve Bitcoin through SideSwap, a federation member with a peg-out authorization key. That activity reduced the reserve to 197 BTC. Blockstream said it patched the affected bridge nodes within ten hours and released Elements v23.3.4 on Wednesday; Liquid resumed producing blocks and processing transactions on Thursday, though peg-outs remain disabled while recovery continues.
Blockstream said it engaged in talks with the exploiters but that participation in negotiations should not be read as acceptance of their demands, which the attackers published publicly. In a transaction on Wednesday the exploiters criticized the project's security spending and demanded roughly a 10% payment, framing it as a bug bounty. Blockstream rejected that framing and said taking assets without authorization is a crime and not "white-hat activity."
Rather than meeting the attackers' terms, Blockstream stated it will pursue "every lawful avenue" to recover the funds, including working with law enforcement, exchanges and forensic specialists. The company also warned of scammers targeting node operators with fake update sites as the final stage of recovery continues.
Keep Reading

Zodia Custody CEO Julian Sawyer steps down, becomes adviser

Albuquerque Bans Bitcoin ATMs, Giving Operators 45 Days to Remove Them

Metaplanet cuts executive reward pool by 41%, extinguishes $220 million in value

EU Regulator Says Prediction Markets Are 'Rife With Inside Trading'
Original source: Decrypt