TechNewsReel
Live

Blockstream Rejects Ransom Demand After Liquid Network Exploit

The company refuses to pay hackers holding nearly 600 BTC after a validation bug drained federation reserves.

TechNewsReel Newsroom · September 11, 2026

Blockstream has officially rejected a ransom demand from hackers who exploited the Liquid Network on September 6, 2026. The decision marks a firm stance against rewarding attackers who compromised the Bitcoin sidechain's infrastructure.

The exploit targeted a confidential transaction validation bug within the Liquid Network federation wallet. Attackers initially stole approximately 4,000 BTC, valued at roughly $320 million at the time of the breach. While the attackers have since returned approximately 3,400 BTC, they continue to hold nearly 600 BTC hostage, prompting the ransom demand that Blockstream has now declined.

The Technical Fallout

The Liquid Network operates as a sidechain where L-BTC is designed to be backed 1:1 by BTC held by the Liquid Federation. Because of the missing funds, L-BTC is currently only about 85% backed. In response to the breach, Blockstream released Elements v23.3.4 to patch the vulnerability. While transaction processing has been restored to the network, peg-outs—the process of moving assets from the sidechain back to the main Bitcoin blockchain—remain disabled.

Industry Implications

Blockstream's refusal to pay the ransom sets a significant precedent for open-source developers and blockchain infrastructure providers. By declining the payment, the company signals that it will not reward criminal activity, even when substantial assets are at stake. In a statement, Blockstream asserted, "We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation."

This approach emphasizes the permanence of the blockchain as a tool for accountability. Blockstream further noted that "transactions do not disappear, and neither does the evidence they leave behind," suggesting that the transparency of the ledger serves as a deterrent and a means of tracking stolen assets.

What Remains

While the immediate vulnerability has been patched and the majority of the funds recovered, the network continues to operate with a deficit in its backing. The industry will be watching to see if the remaining 600 BTC are ever returned or if the attackers attempt further leverage. Additionally, the timeline for the restoration of peg-out functionality remains unconfirmed as the federation manages the aftermath of the reserve drain.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.