Blockstream Says No to Ransom After $47M Bitcoin Exploit on Liquid Network
Blockstream, operator of the Bitcoin sidechain Liquid Network, has refused to pay a ransom to attackers who exploited a software bug to steal 4,000 BTC from its federation wallet on 6 September. The company says it has already recovered around 3,400 BTC, roughly 85% of the stolen funds, and is pursuing the remaining 598.5 BTC (about $47 million) through law enforcement and forensic specialists rather than negotiation.
The attackers exploited a logic flaw in the Elements codebase, the open-source framework behind Liquid, which allowed them to create unbacked pegged tokens and swap them for real BTC. Importantly, the multi-signature system that secures the network's custody was not compromised; this was a software validation flaw rather than a key breach. Blockstream patched the issue quickly and paused network operations during recovery before resuming with updated safeguards.
The attackers publicly demanded a 10% bounty in exchange for returning the funds, framing themselves as white-hat researchers, and threatened further losses to BTC holders if their terms were not met. Blockstream rejected this characterisation, stating that genuine responsible disclosure does not involve draining funds first and negotiating a payout afterward. The company has chosen to treat the incident as theft and is working through legal channels to recover the rest.