Industry News

Blockstream Refuses Ransom Demand After $320M Liquid Network Bitcoin Exploit

UToday · 11 Sept 2026
Key Takeaway Businesses relying on blockchain-based financial infrastructure should ensure vendors promptly patch known vulnerabilities and have a clear incident response and recovery plan in place.

Blockstream, the company behind the Bitcoin sidechain Liquid Network, has confirmed it will not pay a ransom to recover almost 600 Bitcoin still held by attackers following a major security incident. On 6 September, hackers exploited a vulnerability that let them create around 4,000 L-BTC tokens without the Bitcoin needed to back them, then swapped these fake tokens for real BTC through SideSwap's peg-out system. The attack drained roughly 95 percent of the Liquid Federation's reserves, worth about $320 million at the time.

While around 3,400 BTC (about 85 percent of the stolen funds) was returned the following day, roughly 598.5 BTC remains in an address controlled by the attackers. Blockstream firmly rejected the idea that the incident was a form of white-hat disclosure, calling it theft, and said paying a ransom would set a dangerous precedent for open-source Bitcoin development. The company says it will pursue legal action if the remaining funds are not returned, and has released a patched version of its Elements software to fix the underlying flaw.

This incident highlights how vulnerabilities in blockchain infrastructure can lead to losses at a massive scale, even when most funds are eventually recovered.

cryptocurrency Bitcoin vulnerability exploit Blockstream Liquid Network

Summarised by CISO AI from UToday. We link back to every original so you can read it yourself.