Blockstream has firmly rejected ransom demands from attackers holding approximately 598.5 BTC stolen during a Liquid Network security breach on September 6, 2026. The company characterized the incident as criminal theft and vowed to recover the stolen assets through official investigative channels rather than capitulate to extortion.
Nearly 4,000 BTC was initially extracted from Liquid's federation wallet by individuals claiming to be "whitehats." Following Blockstream's deployment of security patches, attackers reimbursed approximately 3,400 BTC to the federation wallet on September 7, representing roughly 85% of the originally withdrawn funds.
The attackers subsequently issued demands via blockchain-based messaging for Blockstream to provide a 10% bounty payment from corporate reserves, threatening that refusal would result in Liquid users absorbing a permanent 15% loss. On September 11, Blockstream published an unequivocal rejection of these demands, stating that "unauthorized asset seizure and conditional withholding constitutes criminal activity, not responsible disclosure."
Technical analysis by Blockstream traced the root cause to a cache-key collision within the confidential transaction verification mechanism. The investigation confirmed that federation cryptographic keys remained secure throughout the incident.
Blockstream stated that attackers retain the option to voluntarily return the Bitcoin consistent with established white-hat security research protocols. Should they decline, the company intends to activate a comprehensive recovery effort involving law enforcement agencies, cryptocurrency exchanges, and blockchain forensic specialists.
The company emphasized that Bitcoin's transparent distributed ledger enables ongoing surveillance of fund movements from addresses associated with the breach. Blockstream noted that blockchain transactions create permanent records and forensic evidence that persists indefinitely.
The Liquid network reinstated block generation following the implementation of emergency software patches, though transaction processing and Bitcoin bridge operations remained temporarily disabled at the time of the company's statement.


