Industry News

Blockstream Refuses Ransom After $270M Bitcoin Exploit on Liquid Network

Dailycoin · 11 Sept 2026
Key Takeaway Businesses relying on blockchain or open-source infrastructure should ensure they have incident response plans that do not default to paying attackers, and should patch and monitor dependencies closely.

Blockstream, the company behind the Liquid Network, has confirmed it will not pay a ransom following a September 6 exploit that saw attackers steal approximately 4,000 BTC. The company described the incident as theft rather than a legitimate security disclosure, and stated it would not use customer funds to pay attackers or set a precedent that forces open-source developers to compensate criminals for returning stolen assets.

Blockstream said the breach stemmed from a bug in Elements, the underlying software for Liquid, rather than any leak of private keys. After releasing a fixed version of the software, normal block generation and transfers resumed on September 10, though the peg-out function remains suspended as a precaution. Roughly 3,400 BTC, about 85% of the stolen funds, has already been returned following ongoing on-chain negotiations, leaving around 598 BTC still unaccounted for.

The company says it is working with law enforcement, exchanges, payment providers and forensic investigators to trace the remaining funds, noting that Bitcoin's transparent transaction history aids identification efforts. Blockstream framed its stance as a broader principle: refusing to legitimise extortion against open-source software maintainers.

Summarised by CISO AI from Dailycoin. We link back to every original so you can read it yourself.