Blockstream Refuses Ransom for 600 BTC in Liquid Exploit
Blockstream has publicly refused to pay a ransom for the return of the remaining 600 BTC tied to a Liquid Network exploit, telling those responsible for the theft that withholding stolen bitcoin is a crime rather than responsible disclosure.
Blockstream has publicly refused to pay a ransom for the return of the remaining 600 BTC tied to a Liquid Network exploit, telling those responsible for the theft that withholding stolen bitcoin is a crime rather than responsible disclosure. The refusal reframes the incident as a law-enforcement matter instead of a whitehat negotiation, leaving the outstanding balance, reserve backing and full recovery status of the Liquid exploit unresolved.
TLDR KEYPOINTS
- Blockstream says it will not pay a ransom for bitcoin stolen from the Liquid Network, per its official statement dated September 11, 2026.
- The headline references roughly 600 BTC still outstanding; reporting puts the precise figure lower, and it has not been reconciled on-chain.
- Block production has resumed but peg-outs remain disabled, so reserve backing and full bridge recovery are not confirmed.
Blockstream’s reported refusal of the ransom demand
The core development is a stated refusal. Blockstream addressed the parties behind the theft of bitcoin from the Liquid Network and said it will not pay a ransom for the return of stolen funds, characterizing the act as a crime and not white-hat activity. For related coverage, see Top 5 Crypto News in the Last 24 Hours: Blockstream Quantum Security Leads.
The company’s own post is the primary evidence for the refusal, and it dates the statement to September 11, 2026. We reproduce it below as direct proof rather than paraphrase. For related coverage, see PolyNext Awards & Conference Dubai 2026: Advancing the Global Dialogue on Plastic Recycling and Circularity.
To those responsible for the theft of bitcoin from the Liquid Network:
Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is…
— Blockstream (@Blockstream) September 11, 2026
Source: @Blockstream on X
What the statement establishes
The authenticated portion confirms the named party (Blockstream), the reported refusal, and the funds referenced (bitcoin stolen from Liquid). The visible embed text is truncated, so any conditions or recovery threats beyond the refusal sentence are not directly verified from the post itself.
Ransom terms and response
Details of the demand are single-sourced and should be treated as attacker assertions, not verified accounting. According to unconfirmed reports from The Block, a Wednesday OP_RETURN message demanded a 10% bug bounty and threatened a 15% loss to holders, framing the outstanding bitcoin as leverage rather than a disclosed vulnerability. The 600 BTC in the headline describes those remaining funds, not the size of any bounty.
What the remaining 600 BTC means for recovery
The headline’s rounded figure sits on top of a more precise, unreconciled number. The Block reported roughly 3,400 BTC had already been returned by the exploiter, leaving 598.5 BTC still outstanding as of September 11, a balance that has not been independently confirmed on-chain.
BTC still outstanding, according to The Block
Funds still at issue
Ownership, on-chain location and recoverability of the outstanding balance remain unverified in first-party evidence. No transfer-time valuation is asserted here; for background only, bitcoin traded near $76,863 at research time, down about 1.4% on the day, with no established causal link to the exploit.
Recovery and incident scope
Blockstream’s initial incident notice estimated that roughly 4,000 BTC, valued at about $320 million, was withdrawn from the Liquid Federation wallet, an approximate incident estimate rather than an audited total. The notice attributed the withdrawals to the SideSwap Peg-out Authorization Key while stating that this key and the other keys were not compromised.
The event should not be read as a Liquid consensus, bridge or smart-contract key failure from the word “exploit” alone. The Liquid Network’s earlier pause following the reported withdrawal is the operational context, and attribution of the actors behind the drain remains a matter of ongoing analysis.
As of September 10 at 10:00 UTC, Blockstream said block production had resumed without transactions and that functionary and bridge node updates were deployed, while peg-outs stayed suspended during reserve recovery. Resumed block production is not the same as restored bridge functionality or confirmed reserve backing.
What would clarify the Liquid exploit’s outcome
Blockstream’s September 9 phishing advisory warns that impersonators are exploiting the incident with fake reimbursement, re-peg and mandatory-update messages, and states that recovery does not require users to move funds, disclose a recovery phrase or install emailed software. That user-protection guidance is a concrete, verifiable step distinct from the ransom standoff.
Three pieces of evidence would move this story from partial to established: an untruncated, attributable Blockstream statement; a full technical incident report; and corroborated, explorer-level fund movements confirming both the outstanding balance and any returns. A subsequently confirmed return of funds must be distinguished from a promise or demand concerning their return.
Recovery prospects and the incident’s final scope cannot be determined from the current evidence set. What is confirmed is the refusal itself, the suspended peg-outs, and an outstanding balance that no independent party has yet reconciled.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Defiliban · Ada Michael
Ada Michael
@ada-michael