Industry News

Blockstream Refuses to Pay Ransom After $320 Million Liquid Network Exploit

Blockonomi · 11 Sept 2026
Key Takeaway Businesses relying on blockchain infrastructure should ensure software is promptly patched and understand that partial fund backing can persist after an incident until full recovery is confirmed.

Blockstream has publicly rejected any ransom demand from the attackers behind a recent exploit of its Liquid Network, a Bitcoin sidechain. The company said the incident cannot be classed as white-hat hacking, since the attackers took funds without authorisation and continue to withhold part of them. Blockstream has warned it may pursue legal action if the remaining Bitcoin is not returned.

The attack on 6 September exploited a software flaw that let attackers mint around 4,000 L-BTC tokens without backing them with real Bitcoin. Using SideSwap's peg-out system, they then converted these fraudulent tokens into genuine Bitcoin drawn from federation reserves, which held about 4,200 BTC before the attack. Roughly 3,400 BTC was later returned, but about 598.5 BTC remains under attacker control, worth a significant sum given the total loss was estimated at around $320 million at the time.

Blockstream has released a patched version of its Elements software to close the exploited vulnerability, and block production and transactions have resumed. However, L-BTC remains only about 85% backed until the outstanding funds are recovered or another resolution is found.

cryptocurrency Blockstream Liquid Network ransom vulnerability

Summarised by CISO AI from Blockonomi. We link back to every original so you can read it yourself.