Blockstream Says No to Ransom Demands as Liquid Hackers Hold 600 BTC
0
0

Blockstream says it will not negotiate with the hackers behind the Liquid Network exploit, arguing that withholding other parties’ funds is criminal rather than a legitimate “disclosure” effort. In a statement released Friday, the Bitcoin infrastructure firm said it engaged with the attackers in good faith to try to recover user assets—but will refuse any demand for a bounty paid from Blockstream’s own funds.
The dispute centers on remaining assets tied to the Liquid sidechain, after self-described “white-hat” actors withdrew funds earlier this month and later partially returned them. Blockstream’s position signals that it expects authorities and market participants to help handle any unresolved recovery work, rather than relying on further onchain payments or messages from the exploit actors.
Key takeaways
- Blockstream rejects the hackers’ demand for an onchain “bounty” payment, calling it theft and not responsible disclosure.
- After the Liquid incident, 3,400 BTC were reportedly returned, leaving roughly 598 BTC still outstanding.
- Liquid resumed block production after emergency updates, but transactions and transfers into and out of the network remain suspended.
- Blockstream says it will involve law enforcement, exchanges, service providers, and forensic specialists if assets are not returned voluntarily.
Blockstream draws a hard line on ransom-style demands
Blockstream said the actors took assets without authorization and then withheld their return, describing the behavior as a crime rather than a security intervention. The company framed its response as an attempt to recover user funds while refusing to accept the attackers’ terms.
According to Blockstream, it previously engaged with the hackers in what it characterized as good faith, with the goal of getting user assets back. That engagement appears to have ended once the hackers issued further demands—specifically that Blockstream pay a 10% bounty from its own funds via an onchain message.
Those demands, Blockstream said, were accompanied by warnings that Liquid holders would otherwise face additional losses. In the broader public discussion of the incident, the bounty demand was tied to messages shared through accounts associated with the Jan3 organization and former Blockstream executive Samson Mow.
How the Liquid exploit unfolded—and what remains unresolved
Liquid is a Bitcoin sidechain that relies on a federation model. On Sept. 6, it paused operations after “white-hat” actors allegedly withdrew approximately 4,000 BTC from its federation wallet. At the time, the funds were described as worth about $320 million.
In the days that followed, the actors reportedly returned 3,400 BTC after Blockstream said that affected bridge nodes were patched. The partial return left about 598 BTC outstanding.
Liquid then moved toward recovery: Blockstream said block production resumed on Thursday after emergency software updates. The resumption, however, did not fully restore normal activity. The network produced empty blocks, and transactions and Bitcoin transfers into and out of the Liquid network remained suspended—an important distinction for users trying to understand whether access and settlement are actually back online.
Blockstream’s current stance suggests that the company views the remaining funds as still improperly held and subject to legal and investigative processes, rather than as an outstanding item to be settled through further payments.
Why Blockstream’s refusal matters for users and market participants
For Liquid users, the difference between a security patch response and a negotiation for payment is more than semantics. Blockstream’s position affects how exchanges, custody providers, and liquidity operators might approach disputed assets and withdrawal processes while the network remains partially paused.
If the outstanding BTC remain tied to unauthorized access, market participants face practical questions: whether certain movements will be enabled, what compliance steps are required if funds are traced, and how to treat any claims made by the exploit actors. Blockstream’s call to coordinate with law enforcement, exchanges, service providers, and forensic specialists indicates it expects the resolution to be handled through investigation and institutional processes rather than continued direct settlement with the perpetrators.
There’s also a potential trust implication. Liquid’s federation depends on coordination among participants and the integrity of bridge mechanics. By accusing the actors of theft and rejecting the bounty demand, Blockstream is effectively telling stakeholders not to treat “white-hat” framing as a substitute for legal justification or user consent.
At the same time, Liquid has already demonstrated technical responsiveness: it issued emergency updates, patched bridge node issues, and resumed block production. That mix—some operational recovery on the infrastructure side, paired with a hard legal stance on remaining assets—helps explain why the network may be technically active while still restricting user transfers.
What to watch next
The immediate focus is whether the remaining roughly 598 BTC will be returned voluntarily, or whether Blockstream’s planned escalation to authorities and investigative partners will lead to identification and recovery efforts. Separately, users should monitor when (and how) Liquid’s suspension on transactions and Bitcoin transfers into and out of the network is lifted after the latest updates—and whether any additional security confirmations are required before full operations resume.
This article was originally published as Blockstream Says No to Ransom Demands as Liquid Hackers Hold 600 BTC on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.
0
0
Securely connect the portfolio you’re using to start.





