TechNewsReel
Live

Blockstream Refuses Ransom for $47 Million in Bitcoin After Liquid Exploit

The company has ceased negotiations with attackers who returned most stolen funds but demanded a bounty for the remainder.

TechNewsReel Newsroom · September 11, 2026

Blockstream has ended negotiations and refused to pay a ransom for the return of approximately 598.5 BTC following a major exploit of the Liquid Network. The company is now pursuing law enforcement and forensic specialists to recover the remaining assets, which are valued at roughly $47 million.

The incident began on Sunday, September 6, 2026, when attackers drained approximately 4,000 BTC—worth about $320 million—from the Liquid sidechain. By the following Monday, the attackers had returned 3,400 BTC, representing roughly 85% of the stolen total. However, the return of the final 598.5 BTC was contingent on a payment demand. Blockstream has since rejected this demand, explicitly labeling the act as criminal theft rather than a legitimate security discovery.

The Technical Exploit

The breach was made possible by a technical flaw in the Elements software used by Liquid nodes. Specifically, the attackers exploited a vulnerability in how these nodes cache range proof verifications. This flaw allowed the actors to mint unbacked L-BTC, which they then swapped for reserve Bitcoin through SideSwap, a federation member of the network.

Blockstream responded rapidly to the breach, patching bridge nodes within ten hours of the event. To permanently resolve the vulnerability and secure the network, the company released a software update, Elements v23.3.4, on the following Wednesday.

Redefining White-Hat Activity

This confrontation highlights a growing tension in the decentralized finance (DeFi) and sidechain sectors regarding the line between "bug bounties" and ransomware. While some attackers frame the seizure of funds as a way to force security improvements, Blockstream is asserting a hard line against such coercion.

According to Blockstream, "Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft." By refusing to pay, the company is signaling that unauthorized asset seizure remains a crime regardless of whether the attacker intends to return the funds for a fee.

Industry Implications

The decision sets a significant precedent for open-source developers and blockchain infrastructure providers. It suggests that companies should not be coerced into paying ransoms that exceed standard economic participation or established bounty programs. If the industry continues to reward "forced" exploits, it risks incentivizing a culture of grey-hat activity where security is only improved after a theft occurs. By standing firm, Blockstream aims to protect the integrity of responsible disclosure and discourage the weaponization of software vulnerabilities for financial gain.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.