Blockstream has refused to pay a ransom for the return of approximately $47 million in Bitcoin following an exploit on the Liquid Network sidechain.
Around 4,000 BTC was drained from Liquid on Sunday. The attackers returned 3,400 BTC on Monday, leaving 598.5 BTC unmoved at the withdrawal address.
The exploit and response
A flaw in how Liquid nodes cache range proof verifications allowed attackers to mint unbacked L-BTC and swap it for reserve Bitcoin through SideSwap. Blockstream patched bridge nodes within ten hours and released Elements v23.3.4 on Wednesday. Liquid resumed block production and transaction processing Thursday, though peg-outs remain disabled as a precautionary measure during recovery efforts.
Blockstream's stance on the ransom demand
In a statement, Blockstream said: "Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft."
The company stated it will not be "a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom." It also said it will not cover any shortfall from users, noting that "Bitcoin is hard money and can't be minted without costs."
Next steps
Blockstream said it will pursue "every lawful avenue" with law enforcement, exchanges, and forensic specialists to trace the remaining funds. The company warned that "transactions do not disappear, and neither does the evidence they leave behind."
The exploiters had demanded 10% of the stolen amount as a bug bounty, threatening a 15% loss for users otherwise. Blockstream's participation in earlier talks with the attackers "should not be mistaken for acceptance of the actions taken nor of the terms being demanded," the company clarified.


