EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Blockstream refuses extortion request, Liquid hackers seize 600 bitcoins

2026-09-11 20:15:17
Bookmark

Blockstream refuses to negotiate: characterizes hacker compensation as theft rather than "responsible disclosure"

Blockstream, a blockchain infrastructure company, said it will not negotiate with so-called "hackers" in recent Liquid network incidents. The company maintains that the reward is theft rather than so-called "responsible disclosure."

In a statement released on Friday, Blockstream pointed out that the company has contacted attackers in good faith in order to recover user funds, but will never meet its conditions. At the heart of the controversy is the remaining bitcoins held after the Liquid Alliance network outage earlier this month. Blockstream emphasized that the behavior has crossed a clear line: unauthorized acquisition of assets and seizure and return them constitutes a crime, rather than a well-intentioned act aimed at improving security.

Key Points

  • Blockstream refused to pay the requested "reward" and said the remaining funds should be voluntarily returned unconditionally.
  • After trying to communicate, if the funds are not returned, Blockstream said it will upgrade its response measures and work together with law enforcement agencies, exchanges, service providers and forensic experts.

The incident began when an attacker who called himself a "white hat" extracted approximately 4,000 bitcoins from the Liquid Alliance wallet. After patching the bridge node, the attacker returned approximately 3,400 bitcoins, leaving approximately 598 bitcoins outstanding. Although Liquid resumed block production with an emergency update, the network's transaction and transfer functions were still suspended at the time of the report's release.

Blockstream draws a red line on "bounty" demands

Blockstream's position is unequalled (clear and unambiguous): It will not pay anything to recover assets it believes were transferred through unauthorized use. The company called the act "theft" and made it clear that it did not have the nature of a "white hat" activity or "responsible disclosure."

Regarding the timing and intention of the interaction, Blockstream said that the company had cooperated with hackers in good faith to try to recover user funds, but would never accept the attacker's extortion requests. According to reports, these requirements were conveyed through on-chain messages. The source claimed that if Blockstream did not cooperate, Liquid holders would face a 15% loss, and also required Blockstream to use its own funds to pay a reward equivalent to 10% of the requested amount. The online call was publicly shared by Samson Mow, CEO of Jan3 and former chief strategy officer of Blockstream.

In response, Blockstream urged remaining Bitcoin holders to return the funds involved without other conditions. If voluntary restitution does not occur, the company will initiate a tracing and identification process-using collaboration with law enforcement, exchanges, service providers and forensic experts to lock in the flow of funds.

Current Status of Liquid Network: Block production resumes, transfers are still suspended

Liquid is a Bitcoin sidechain based on the alliance model. The interruption came after the attacker, who called himself a "white hat", extracted approximately 4,000 bitcoins from the Liquid Alliance wallet, valued at approximately $320 million at the time. Subsequently, Liquid suspended operations. Due to urgent repairs involving bridging components and network programs, resuming normal activities requires priority security concerns.

Since then, the attacker returned 3,400 bitcoins after Blockstream announced that the affected bridge node had been patched. According to subsequent reports, there are still about 598 bitcoins that have not yet been returned. Blockstream's latest statement characterizes these remaining balances as funds that should not be withheld. The company's plan to shift from engagement to potential investigation and legal coordination suggests it views the situation as recoverable loss that requires external law enforcement support rather than a negotiated remedy.

Liquid's recovery was partial and cautious. After an emergency software update, the network resumed block production. However, the newly produced blocks were empty, reflecting that the core transaction flow was not fully restored immediately after the repair. At the same time, transactions into and out of Liquid and Bitcoin transfers remain suspended. This is critical for users because even if the network is "restarted" in generating blocks, its functionality may still be limited if the transfer relies on bridging components or other security measures that require additional verification.

The contrast between the resumption of block production and the continued suspension of transfers highlights the common reality of sidechain and alliance-based systems in the post-incident phase: restoring consensus activity is not the same as restoring end-to-end flow of assets. Before reactivating the deposit and withdrawal workflow, users and integrators often need to ensure that the issuance and redemption paths are secure.

How refusing to pay a bounty changes the dynamics of the situation

The impact of refusing to pay the requested bounty is not only on the outcome, but also on the adjustment of incentives. When attackers try to turn exposure into gain, companies must decide whether entering into negotiations will set a precedent that encourages future events. Blockstream apparently chose the deterrent route-arguing that paying a reward would legalize unauthorized possession of assets as a "disclosure" process.

The company's approach has also changed the path of practical problem solving. Instead of relying on attackers to continue to respond to pressure, Blockstream is signaling that it will turn to forensic tracing and coordinated actions with third parties to help identify the flow of funds and locate responsible parties. This includes exchanges and service providers that may freeze or track funds based on jurisdiction and access rights.

There is tension in the broader narrative: The attacker had previously described the operation as a "white hat" and some funds had been returned after the technology was repaired. But Blockstream's information emphasizes that returning some assets does not relieve the liability to detain remaining assets under threat of payment.

For Liquid users, the key outstanding question is simple: Will the approximately 598 bitcoins related to this incident be returned unconditionally? Even if certain functions are restored to the network, asset recovery schedules may depend on the interaction between technical fixes, fund-tracking capabilities, and any subsequent legal or regulatory steps.

Looking forward, traders, wallet providers and bridge operators should pay close attention to whether Liquid transfers continue to remain suspended, whether additional emergency patches are needed, and, most importantly, whether the remaining bitcoins are voluntarily restored as required by Blockstream, rather than conditional payments.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP