TLDR
- Blockstream has rejected ransom demands for approximately 598.5 BTC still controlled by attackers after the Liquid Network security breach
- Attackers initially extracted close to 4,000 BTC from Liquid’s federation wallet on September 6, 2026
- Approximately 3,400 BTC was sent back following Blockstream’s vulnerability fix, leaving roughly 15% unaccounted for
- Attackers issued an ultimatum demanding 10% bounty from Blockstream’s treasury or Liquid users would face a 15% permanent loss
- Blockstream plans to collaborate with authorities, cryptocurrency exchanges and blockchain forensics experts to track and retrieve the stolen Bitcoin
Blockstream has taken a firm stance against paying extortion demands from attackers who continue to control roughly 598.5 BTC following the Liquid Network security incident. The blockchain infrastructure company characterized the situation as outright theft and announced its intention to recover the assets through legal and investigative means.
The security breach originated on September 6, 2026, when individuals claiming to be “whitehats” extracted nearly 4,000 BTC from the federation wallet of Liquid. That quantity represented approximately $320 million in value at that moment.
Liquid operates as a Bitcoin sidechain developed and operated by Blockstream. Following the unauthorized withdrawal, network operations were temporarily halted while technical teams investigated and addressed the security vulnerability.
Blockstream’s investigation revealed the root cause to be a cache-key collision within the confidential transaction verification system. Importantly, the company verified that the federation’s cryptographic keys remained secure throughout the incident.
Once Blockstream implemented fixes across the compromised bridge infrastructure, the individuals responsible sent back 3,400 BTC to the federation’s address on September 7. This reimbursement accounted for roughly 85% of the originally extracted amount.
The outstanding 598.5 BTC remained in an address under the attackers’ control. At the moment of the partial reimbursement, these coins held a value approaching $47 million.
The attackers subsequently modified their position. Using blockchain-based communications, they insisted that Blockstream provide a 10% bounty payment from its corporate reserves. Alternatively, they threatened that users of the Liquid network would permanently lose 15% of their holdings.
Blockstream Dismisses Extortion Attempt
On September 11, Blockstream issued a definitive rejection via its X social media account. The organization stated it would not comply with ransom demands for stolen cryptocurrency and disputed the attackers’ characterization of their actions as responsible vulnerability disclosure.
“Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft,” the company said.
Blockstream further contended that developers of open-source software should not face financial extortion when vulnerabilities are exploited in code they maintain, especially when they have no direct financial interest in the affected network.
The company acknowledged that it had participated in communications with the attackers during initial discussions but emphasized that such engagement did not constitute acceptance of the withdrawal or agreement to any bounty arrangement.
What Happens Next
Blockstream indicated that the attackers retain the option to voluntarily return the cryptocurrency and align their actions with legitimate white-hat security research principles. Absent such cooperation, the company intends to mobilize law enforcement agencies, cryptocurrency trading platforms, service providers and blockchain forensics specialists.
The transparent nature of Bitcoin’s distributed ledger enables ongoing surveillance of fund movements originating from addresses associated with the breach, regardless of attempts to fragment the holdings across multiple wallets.
Blockstream referenced a comparable investigation following the Coldhead security incident, during which Galaxy Research documented 1,561 BTC that remained stationary after attacker addresses were distributed to exchanges and regulatory compliance organizations.
Liquid network operations recommenced on Thursday after emergency software patches were deployed, although transaction processing and Bitcoin deposits and withdrawals remained disabled at the time of this report.
Blockstream communicated to the Bitcoin ecosystem that it would persist in efforts to protect users whose assets were compromised and expressed appreciation for engineers, cryptography experts and security professionals who contributed to identifying and resolving the vulnerabilities.
“Transactions do not disappear, and neither does the evidence they leave behind,” the company said.





