Blockstream Refuses Ransom After $270M Bitcoin Exploit on Liquid Network
Blockstream, the company behind the Liquid Network, has confirmed it will not pay a ransom following a September 6 exploit that saw attackers steal approximately 4,000 BTC. The company described the incident as theft rather than a legitimate security disclosure, and stated it would not use customer funds to pay attackers or set a precedent that forces open-source developers to compensate criminals for returning stolen assets.
Blockstream said the breach stemmed from a bug in Elements, the underlying software for Liquid, rather than any leak of private keys. After releasing a fixed version of the software, normal block generation and transfers resumed on September 10, though the peg-out function remains suspended as a precaution. Roughly 3,400 BTC, about 85% of the stolen funds, has already been returned following ongoing on-chain negotiations, leaving around 598 BTC still unaccounted for.
The company says it is working with law enforcement, exchanges, payment providers and forensic investigators to trace the remaining funds, noting that Bitcoin's transparent transaction history aids identification efforts. Blockstream framed its stance as a broader principle: refusing to legitimise extortion against open-source software maintainers.