Industry News

Blockstream Refuses to Pay Ransom Over $47M Bitcoin Exploit

Crypto news · 11 Sept 2026
Key Takeaway Businesses relying on crypto infrastructure or open-source financial software should treat any unauthorised fund withdrawal as theft rather than negotiate ransom terms with attackers, and ensure incident response plans include rapid patching and clear public communication.

Blockstream has confirmed it will not pay a ransom to recover the remaining Bitcoin taken during an exploit of its Liquid Network federation wallet. Nearly 4,000 BTC was withdrawn on 6 September, and while 3,400 BTC (about 85%) was returned the following day, roughly 598.5 BTC remains outstanding.

The unidentified actors initially described themselves as "whitehats" and communicated with Blockstream through messages embedded in Bitcoin transactions, demanding the vulnerability be fixed before returning funds. Blockstream says it patched its bridge nodes and confirmed this through a signed message, but rejects the actors' framing of their conduct as responsible disclosure. The company stated plainly that taking assets without authorisation and withholding their return is theft, not ethical hacking.

Blockstream argues that open-source software developers should not be forced to pay ransoms disproportionate to their stake in a project simply because someone exploited their code. No public agreement authorised the actors to keep any portion of the funds as a bounty, and the dispute over the remaining $47 million worth of Bitcoin is ongoing.

Summarised by CISO AI from Crypto news. We link back to every original so you can read it yourself.