NewsCryptoBlockstream Refuses Ransom Demand for Remaining Bitcoin Tied to Liquid Exploit

Blockstream Refuses Ransom Demand for Remaining Bitcoin Tied to Liquid Exploit

Author: DefiLiban·

Key Takeaways

  • Blockstream stated on September 11, 2026 that it will not pay a ransom for the return of bitcoin stolen from the Liquid Network, characterizing the theft as a crime rather than white-hat activity.
  • Unconfirmed reports from The Block indicate an on-chain OP_RETURN message demanded a 10% bug bounty and threatened a 15% loss to holders.
  • Approximately 3,400 BTC of the estimated 4,000 BTC initially withdrawn from the Liquid Federation wallet has reportedly been returned, leaving about 598.5 BTC outstanding as of September 11, a figure not yet confirmed through on-chain analysis.
  • Block production on the Liquid Network resumed without transactions as of September 10, but peg-outs remained suspended, leaving the standard exit path from the sidechain closed.
  • Blockstream issued a September 9 phishing advisory warning that impersonators were distributing fake reimbursement and update messages, and stated users do not need to move funds, disclose recovery phrases, or install emailed software.
Blockstream Refuses Ransom Demand for Remaining Bitcoin Tied to Liquid Exploit

Blockstream has publicly refused to pay a ransom for the return of bitcoin stolen in an exploit involving the Liquid Network, the federated bitcoin sidechain operated by Blockstream, saying that unauthorized asset transfers and withholding the funds are criminal acts rather than responsible disclosure. The statement leaves the exact outstanding balance, the status of reserve backing and the full recovery of the Liquid system unresolved.

Blockstream rejects ransom demand

In an official statement dated September 11, 2026, Blockstream addressed the parties responsible for the theft and said it would not pay a ransom for the return of the stolen funds. The company characterized the incident as a crime rather than white-hat activity. The statement was published by @Blockstream on X.

To those responsible for the theft of bitcoin from the Liquid Network: Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is… — Blockstream (@Blockstream) September 11, 2026

The authenticated portion of the post confirms Blockstream as the speaker, its refusal to pay and the fact that the funds were bitcoin taken from Liquid. The visible text is truncated, so any conditions, recovery threats or other details that may follow the quoted portion cannot be independently verified from the post itself.

The refusal shifts the dispute away from a possible white-hat negotiation and toward a law-enforcement matter. In practical terms, any further return of the outstanding funds now depends on the exploiter or on the recovery work already underway, not on a negotiated payment. Details of the demand remain based on single-source reporting and should be treated as claims by the alleged attackers rather than verified accounting.

According to unconfirmed reports from The Block, a Wednesday OP_RETURN message — an opcode that allows small data messages to be embedded directly in bitcoin transactions — demanded a 10% bug bounty and threatened a 15% loss to holders. The message reportedly presented the outstanding bitcoin as leverage, rather than as funds connected to a disclosed vulnerability. The roughly 600 BTC cited in the headline refers to the remaining funds and not to the size of the alleged bounty.

Outstanding balance remains unresolved

The 600 BTC figure is a rounded reference to a more precise but unreconciled balance. The Block reported that approximately 3,400 BTC had already been returned by the exploiter, leaving 598.5 BTC outstanding as of September 11. That figure has not been independently confirmed through on-chain analysis.

The ownership, on-chain location and recoverability of the remaining funds have not been established by first-party evidence. No transfer-time valuation is asserted here. For background only, bitcoin was trading near $76,863 at the time of research, down approximately 1.4% on the day; no causal connection between that price movement and the Liquid incident has been established.

Scope of the Liquid incident

Blockstream’s initial incident notice estimated that approximately 4,000 BTC, valued at about $320 million, had been withdrawn from the Liquid Federation wallet. The figure was an incident estimate, not an audited total. The notice attributed the withdrawals to the SideSwap Peg-out Authorization Key while stating that this key and the other keys had not been compromised. The incident notice is available through Blockstream’s status page.

The use of the term “exploit” alone does not establish that the Liquid consensus system, a bridge or a smart-contract key failed. The Liquid Network had previously paused operations following the reported withdrawal, while attribution of the actors behind the drain remained under analysis.

As of September 10 at 10:00 UTC, Blockstream said block production had resumed without transactions and that updates had been deployed to functionary and bridge nodes. Peg-outs, however, remained suspended while reserve recovery continued. On Liquid, peg-outs are the functionary-signed operation that moves assets from the sidechain back to the bitcoin base layer, so their continued suspension leaves the standard exit path closed even with blocks being produced. The resumption of block production therefore did not represent restored bridge functionality or confirmed reserve backing.

Security warnings and evidence still needed

In a September 9 phishing advisory, Blockstream warned that impersonators were using the incident to distribute fake reimbursement, re-peg and mandatory-update messages. The company said users did not need to move funds, disclose a recovery phrase or install software received by email to take part in recovery. The warning is a separate, verifiable user-protection measure and does not resolve the ransom dispute.

Several pieces of evidence would be needed to establish the incident’s final status: an attributable and untruncated Blockstream statement; a complete technical incident report; and corroborated explorer-level transactions confirming both the outstanding balance and any returned funds. A confirmed transfer of funds must also be distinguished from a promise or demand concerning their return. Restored peg-outs, rather than resumed block production, would be the operational marker that the bridge itself is functioning again.

The available evidence does not establish final scope of the incident or the prospects for recovery. What is confirmed is Blockstream’s refusal to pay the ransom, the continued suspension of peg-outs and an outstanding bitcoin balance that no independent party has yet reconciled.