EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Blockstream refuses to pay ransom to recover $47 million left after the Liquid hack

2026-09-12 00:42:30
Bookmark

Blockstream refuses to pay a ransom to recover the approximately 598.5 BTC remaining on Liquid Network

Despite days of negotiations with those responsible for the theft, Blockstream announced that it will not pay a ransom in exchange for the approximately 598.5 BTC lost after a recent vulnerability attack on Liquid Network.

A major flaw in Liquid Network led to the theft of 4,000 BTC

Liquid Network, the Bitcoin sidechain operated by Blockstream, was attacked on Sunday, resulting in the looting of approximately 4,000 BTC (worth approximately US$320 million) from its reserves. Due to a vulnerability in the way the Liquid node handles proof-of-range verification, attackers were able to mince unsupported L-BTC tokens and exchange them for real bitcoins through SideSwap. SideSwap, as a Storm member with withdrawal authorization, allowed the transfer without knowing it. The move reduced the network's Bitcoin reserves to 197 BTC.

Blockstream responded quickly to the intrusion, patching the affected bridge nodes within ten hours, and released Elements v23.3.4 on Wednesday. As of Thursday, Liquid Network had resumed block production and transaction processing, but to prevent accidents, the withdrawal function was temporarily disabled. In addition, the company also warned node operators to be wary of scammers using ongoing recovery efforts to promote false updates to websites.

Negotiations broke down over ransom demands

On Monday, the attackers returned 3,400 BTC to Blockstream, equivalent to about 85% of the stolen funds, but still withheld 598.5 BTC, which remained at the original withdrawal address. The negotiations were public, and attackers wrote in the Bitcoin deal that Blockstream had invested only "$1.5 million (possibly even zero)" to protect $5 billion worth of assets and accused the company of "grossly ignoring security." The attacker demanded a 10% reward for the vulnerability, threatening that if Blockstream refused, the holder would face a 15% loss due to its "irresponsibility and stinginess."

Blockstream said its participation in the discussions "should not be misinterpreted as an endorsement of the actions done or the terms proposed." The company clarified that it would not agree to setting a precedent that open source software developers should pay huge ransoms far beyond their financial benefits, and reiterated that it would not make up for users 'losses, emphasizing: "Bitcoin is a hard currency and cannot be forged out of thin air without paying the cost."

Instead, Blockstream promises to work with law enforcement agencies, cryptocurrency exchanges and forensic experts to track down and recover the missing funds if they are not voluntarily returned. The company warned: "Transactions will not disappear, nor will the evidence they leave," and urged attackers to return Bitcoin.

Continuous monitoring and market response

Tuesday's report noted that negotiations were continuing with attackers known as "white-hat hackers" aimed at fully recovering liquidating assets. The incident highlighted the risks of digital asset custody and the continued need for strong security measures across the blockchain network.

In a market where a single Federal Reserve decision or a sudden altcoin listing can change everything in seconds, the importance of mobile market monitoring is growing. Many investors are turning to tools with privacy as a primary feature that allow users to integrate charts, news and portfolio tracking in one interface. Such tools provide real-time charts, smart price alerts, currency-specific news and important macro data without requiring users to create accounts, solving many information gaps such as those exposed by the Liquid Network vulnerability incident.

As the recovery effort continues, Blockstream keeps Liquid Network's withdrawal feature disabled during what it describes as the "final recovery phase", taking a cautious approach until all vulnerabilities are resolved and the missing funds are addressed. The attacker highlighted the contrast between the size of the assets Blockstream manages and the resources it uses for security, claiming that unless its requirements are met, users will suffer unnecessary losses.

The situation remains dynamic, and while Blockstream continues to pursue legal and investigative actions, it also warns its community of potential scams targeting node operators during this period. Industry observers are watching developments closely because the eventual recovery of Bitcoin reserves could set important precedents for future protocol-level security incidents and the handling of ransom demands in the broader ecosystem.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP