Key Highlights
- Blockstream has declined to meet ransom demands for approximately 598.5 BTC retained by attackers after the Liquid Network breach
- Nearly 4,000 BTC was initially extracted from Liquid’s federation wallet by attackers on September 6, 2026
- Approximately 3,400 BTC was reimbursed following Blockstream’s security patch, with roughly 15% still outstanding
- Attackers issued an ultimatum demanding 10% bounty from Blockstream’s treasury or threatened Liquid users with 15% losses
- The company announced plans to collaborate with authorities, cryptocurrency exchanges, and blockchain forensic experts to trace stolen assets
Blockstream has issued a firm rejection of ransom demands from attackers currently holding roughly 598.5 BTC following the Liquid Network security breach. The firm characterized the incident as criminal theft and announced its commitment to recovering stolen assets through official investigative channels.
The security breach unfolded on September 6, 2026, when individuals identifying as “whitehats” extracted nearly 4,000 BTC from the federation wallet belonging to Liquid. Based on market prices at that moment, the withdrawn amount represented approximately $320 million in value.
Liquid operates as a Bitcoin sidechain developed and operated by Blockstream. Following the unauthorized withdrawal, network operators temporarily halted block generation while technical teams investigated and addressed the vulnerability.
Technical analysis by Blockstream traced the root cause to a cache-key collision within the confidential transaction verification mechanism. The investigation determined that federation cryptographic keys remained secure and uncompromised throughout the incident.
Following Blockstream’s deployment of security patches to affected bridge infrastructure, the attackers reimbursed 3,400 BTC to the federation wallet on September 7. This repayment represented approximately 85% of the originally withdrawn funds.
The outstanding balance of 598.5 BTC remained in an address under the attackers’ control. At the time of the partial reimbursement, these remaining coins held a market value approaching $47 million.
Subsequently, the attackers modified their conditions. Using blockchain-based messaging, they issued demands for Blockstream to provide a 10% bounty payment from corporate reserves. They threatened that refusal would result in Liquid users absorbing a permanent 15% loss.
Company’s Firm Response
On September 11, Blockstream published an unequivocal rejection via its official X account. The statement clarified that the company would not submit to extortion demands for stolen asset recovery and disputed the attackers’ characterization of responsible vulnerability disclosure.
“Unauthorized asset seizure and conditional withholding constitutes criminal activity, not responsible disclosure. This behavior does not reflect white-hat ethics. It represents theft,” Blockstream declared.
The company further contended that open-source software maintainers should not face extortion after vulnerability exploitation, especially when those developers lack direct financial interest in the affected network operations.
Blockstream acknowledged previous communication with the attackers conducted in good faith but emphasized that such dialogue never constituted acceptance of the withdrawal or agreement to bounty payments.
Recovery Strategy Moving Forward
According to Blockstream’s statement, the attackers retain the option to voluntarily return the Bitcoin consistent with established white-hat security research protocols. Should they fail to do so, the company intends to activate a comprehensive recovery effort involving law enforcement agencies, cryptocurrency exchanges, financial service providers, and blockchain forensic specialists.
The transparent nature of Bitcoin’s distributed ledger enables ongoing surveillance of fund movements originating from addresses associated with the breach, regardless of subsequent wallet subdivisions or transfers.
Blockstream referenced precedent from the Coldhead security incident, where Galaxy Research documented 1,561 BTC remaining stationary after attacker-controlled addresses were distributed to exchanges and compliance departments.
The Liquid network reinstated block generation on Thursday after implementing emergency software patches, although transaction processing and Bitcoin bridge operations remained temporarily disabled at the time of publication.
Blockstream communicated its ongoing commitment to affected users and expressed appreciation for the engineers, cryptography experts, and security professionals who contributed to vulnerability identification and remediation.
“Blockchain transactions create permanent records, and the forensic evidence they generate persists indefinitely,” the company emphasized.



