Bitcoin

Blockstream Refuses Ransom While Liquid’s Bitcoin Sits 85% Backed

Transactions have restarted but peg-outs are still disabled, and with 598 BTC outside federation control the token backing the network is running at about 85% collateralisation.

⏱ 2 min read Bitcoin
Quick Summary
  • Blockstream refused to pay a 10% bounty demanded by Liquid Network hackers, calling the act theft rather than white-hat activity
  • Roughly 598 BTC remains outstanding after the hackers returned 3,400 BTC of the approximately 4,000 BTC drained on September 6
  • L-BTC is currently backed at about 85% of the Bitcoin it represents, with transactions restarted but peg-outs still disabled while the reserve is rebuilt

Bitcoin infrastructure firm Blockstream has flatly refused to pay a ransom to recover funds still held by the actors behind the Liquid Network exploit, calling their conduct theft rather than responsible disclosure.

No Payment, No Negotiation

‘Taking assets without authorization and withholding their return is a crime, not responsible disclosure,’ Blockstream said on Friday. ‘It is not white-hat activity. It is theft.’

The company acknowledged engaging with the hackers in good faith to retrieve user funds but stated it would not meet their demands. Blockstream urged the attackers to return the remaining Bitcoin voluntarily, warning that if they do not, the firm will coordinate with law enforcement, exchanges, service providers, and forensic specialists to trace the assets and identify those responsible.

The Ransom Demand

The hackers demanded Blockstream pay a 10% bounty from its own funds. The demand was delivered in an onchain message shared by Jan3 CEO and former Blockstream chief strategy officer Samson Mow on Wednesday. The attackers warned that Liquid holders would face a 15% loss if the bounty was not paid.

How the Exploit Unfolded

On September 6, Liquid, a Bitcoin sidechain operated by Blockstream, suspended operations after self-described white-hat hackers withdrew approximately 4,000 Bitcoin from its federation wallet, then valued at around $320 million.

The actors subsequently returned 3,400 BTC after Blockstream confirmed that affected bridge nodes had been patched. That left roughly 598 BTC outstanding and still in the hands of the hackers.

Liquid resumed block production on Thursday following emergency software updates, initially producing only empty blocks. Transactions have since restarted, though peg-outs, the mechanism for moving actual Bitcoin into and out of the network, remain disabled.

What It Means for L-BTC Holders

Liquid held roughly 4,200 BTC in its federation wallet before the attack, meaning the withdrawal took close to 95% of its reserves. With 598 BTC still outside federation control, L-BTC is currently backed at around 85% of the Bitcoin it represents, a figure Samson Mow has stated publicly.

The shortfall is the practical issue for anyone holding the token. Until the remaining Bitcoin is returned or replaced, the peg is short, and that is the reason peg-outs stay disabled while block production and transactions run. The vulnerability itself was patched in an emergency release, Elements v23.3.4.

Blockstream’s firm stance signals it will not set a precedent of rewarding unauthorised access to its network, regardless of whether the actors frame their actions as a security intervention.

⚖️ Our Verdict 📉 Bearish Signal

Blockstream's position is defensible and probably correct: paying a bounty to someone who took the funds first would price every future exploit. And 85% of the Bitcoin came back, which is a better outcome than most exploited networks manage. But the number that matters to a holder is the other one. With 598 BTC still outside federation control, L-BTC is running at roughly 85% backing, peg-outs are disabled while the reserve is rebuilt, and there is no agreed route to closing the gap. A sidechain whose peg is short is not the same asset it was on 5 September.