Bitcoin infrastructure firm Blockstream has flatly refused to pay a ransom to recover funds still held by the actors behind the Liquid Network exploit, calling their conduct theft rather than responsible disclosure.
No Payment, No Negotiation
‘Taking assets without authorization and withholding their return is a crime, not responsible disclosure,’ Blockstream said on Friday. ‘It is not white-hat activity. It is theft.’
The company acknowledged engaging with the hackers in good faith to retrieve user funds but stated it would not meet their demands. Blockstream urged the attackers to return the remaining Bitcoin voluntarily, warning that if they do not, the firm will coordinate with law enforcement, exchanges, service providers, and forensic specialists to trace the assets and identify those responsible.
The Ransom Demand
The hackers demanded Blockstream pay a 10% bounty from its own funds. The demand was delivered in an onchain message shared by Jan3 CEO and former Blockstream chief strategy officer Samson Mow on Wednesday. The attackers warned that Liquid holders would face a 15% loss if the bounty was not paid.
How the Exploit Unfolded
On September 6, Liquid, a Bitcoin sidechain operated by Blockstream, suspended operations after self-described white-hat hackers withdrew approximately 4,000 Bitcoin from its federation wallet, then valued at around $320 million.
The actors subsequently returned 3,400 BTC after Blockstream confirmed that affected bridge nodes had been patched. That left roughly 598 BTC outstanding and still in the hands of the hackers.
Liquid resumed block production on Thursday following emergency software updates, initially producing only empty blocks. Transactions have since restarted, though peg-outs, the mechanism for moving actual Bitcoin into and out of the network, remain disabled.
What It Means for L-BTC Holders
Liquid held roughly 4,200 BTC in its federation wallet before the attack, meaning the withdrawal took close to 95% of its reserves. With 598 BTC still outside federation control, L-BTC is currently backed at around 85% of the Bitcoin it represents, a figure Samson Mow has stated publicly.
The shortfall is the practical issue for anyone holding the token. Until the remaining Bitcoin is returned or replaced, the peg is short, and that is the reason peg-outs stay disabled while block production and transactions run. The vulnerability itself was patched in an emergency release, Elements v23.3.4.
Blockstream’s firm stance signals it will not set a precedent of rewarding unauthorised access to its network, regardless of whether the actors frame their actions as a security intervention.


