Blockstream has issued a firm statement rejecting a ransom demand from the hackers responsible for the recent exploit targeting the Liquid Network, one of Bitcoin‘s major sidechains. Despite continued negotiations, the company clearly stated it will not pay for the return of nearly 600 Bitcoin that remain under the attackers’ control.
Details of the Liquid Network Breach
On September 6, attackers leveraged a vulnerability within the Liquid Network to mint approximately 4,000 L-BTC tokens without the required Bitcoin collateral. Using SideSwap’s peg-out system, they managed to redeem these synthetic tokens for almost 4,000 real Bitcoin, which were taken directly from the Liquid Federation reserves.
The Liquid Network is structured so that each L-BTC must be backed one-to-one by Bitcoin held by the Liquid Federation. The reserve wallet housed around 4,200 BTC before the breach, and the exploit resulted in the loss of about 95% of those holdings, valued at roughly $320 million at the time of the incident.
Following the attack, the responsible group returned most of the stolen funds. On September 7, roughly 3,400 BTC were transferred back to the Liquid Federation, representing nearly 85% of the original theft. However, the attackers retained control of nearly 600 BTC, valued in the tens of millions of dollars.
Blockstream’s Response and Legal Action
Blockstream made it clear that it would not participate in any ransom scheme, stating that the company does not view this incident as the work of white-hat hackers and will not reward criminal activity with payment. The firm emphasized its position in an official statement:
“We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation.”
The company added that it is committed to pursuing all available legal remedies if the remaining Bitcoin is not returned, warning the perpetrators that their digital footprints are permanently recorded on the blockchain.
Blockstream also pointed to the broader consequences for the Bitcoin ecosystem, arguing that giving in to such demands could pose serious risks for open-source developers. The company’s leadership, including former chief strategy officer Samson Mow, has provided ongoing updates regarding recovery efforts and made it clear that repayment of all stolen assets remains a top priority.
Ongoing Recovery and Technical Response
Following the breach, Blockstream released Elements v23.3.4 to resolve the exploited vulnerability. Block production has since recommenced, and Liquid Network transactions are being processed as usual. However, with almost 600 BTC outstanding, L-BTC remains only about 85% backed.
Samson Mow noted that the network has stabilized but stressed that complete backing will only be restored once the remaining funds are recovered. Blockstream reiterated that Bitcoin transactions are always auditable, with each transfer permanently recorded on the blockchain.
“Transactions do not disappear, and neither does the evidence they leave behind,” the company warned, encouraging those responsible to return the remaining coins voluntarily.
Industry observers point to the growing importance of resilient infrastructure and transparent market operations. While traditional markets rely on complex brokers, a shift is underway as Wall Street increasingly explores Web3. Investors are now holding tokenized assets, such as shares of major U.S. companies, gold, and silver, directly in their crypto wallets through platforms like 1stepSwap, which automatically aggregates the best market prices and eliminates the need for intermediaries.
Blockstream left open the possibility for attackers to resolve the incident without further escalation, stating that a responsible resolution is still possible. The company remains committed to recovering all stolen Bitcoin and safeguarding its open-source community.




