Blockstream has rejected a ransom demand from the actors still holding nearly 598 BTC following the $320 million security incident that disrupted the Liquid Network.
The group, which describes itself as white-hat hackers, returned approximately 3,400 BTC after Blockstream patched the vulnerability behind the exploit. However, about 598.5 BTC, worth roughly $47 million at the time, remains outstanding.
Blockstream has now made clear that it will not pay a ransom to recover the remaining Bitcoin.
Blockstream Rejects 10% Bitcoin Ransom
The dispute escalated after the actors demanded that Blockstream pay a 10% bounty from its own funds in exchange for the remaining Bitcoin.
The group also warned that refusing the demand could leave Liquid holders facing a potential 15% loss, according to messages sent through Bitcoin's OP_RETURN mechanism.
Blockstream rejected that characterization.
The company said unauthorized removal and withholding of assets does not constitute responsible disclosure and argued that paying the demand would establish a precedent for attackers to take funds first and negotiate compensation afterward.
Blockstream said it remains focused on recovering the funds and protecting affected users.
Nearly 4,000 BTC Was Initially Withdrawn
The incident began on September 6, when approximately 4,000 BTC was withdrawn from Liquid's federation wallet, which held roughly 4,200 BTC.
The withdrawal represented about 95% of the wallet's reserves and was initially valued at approximately $320 million. Reuters reported that the funds were withdrawn through Liquid's SideSwap-based peg-out process, while the relevant cryptographic key itself was not compromised.
Investigations later linked the incident to a vulnerability in Elements, the open-source software underlying Liquid.
The flaw allowed invalid L-BTC to pass through transaction validation and ultimately be converted into real BTC through the peg-out process. Chainalysis described the incident as an exploitation of Liquid's transaction-validation software that enabled the creation of unbacked L-BTC.
Hackers Returned 3,400 BTC
Following the exploit, the actors communicated with Blockstream through messages embedded in Bitcoin transactions.
They initially said the vulnerability needed to be fixed before the funds would be returned.
After Blockstream confirmed that affected bridge nodes had been patched, approximately 3,400 BTC was returned to the Liquid Federation wallet.
That represented roughly 85% of the Bitcoin taken during the incident.
The remaining 598.5 BTC stayed under the control of the actors.
The lack of a publicly disclosed agreement over the retained Bitcoin has become a central issue in the dispute.
Why the "White-Hat" Label Is Contested
The actors have repeatedly described themselves as white-hat hackers.
However, the label has not been independently established as an authorized security exercise or bug bounty.
A conventional white-hat disclosure typically involves identifying a vulnerability and reporting it to the affected project, often under an agreed bug-bounty framework.
In the Liquid incident, the actors first obtained control of a large amount of Bitcoin without authorization and later conditioned the return of the remaining funds on a payment demand.
That distinction is why Blockstream has rejected the ransom characterization and why some security experts have questioned whether the activity should be considered legitimate white-hat research.
Liquid Network Begins Controlled Recovery
The incident temporarily halted Liquid's operations.
Liquid has since released Elements v23.3.4, an emergency software update designed to address the proof-verification cache vulnerability associated with the exploit. The update underwent internal and external reviews before deployment.
The network has now entered a controlled recovery phase.
Block production has resumed, but user transactions and BTC peg operations remain suspended while functionary nodes are monitored and the network state is restored.
Liquid's recovery plan involves three broad stages:
Resume block production while peg operations remain suspended.
Replay transactions that are confirmed as valid.
Resume peg operations after the network state and BTC/L-BTC backing have been fully restored.
The remaining Bitcoin is therefore still a critical part of the recovery process.
The Bigger Bitcoin Security Lesson
The Liquid incident highlights an important distinction between Bitcoin itself and applications built around Bitcoin.
The Bitcoin blockchain was not hacked. Instead, the incident occurred within Liquid, a Bitcoin sidechain that uses its own federation and infrastructure to provide faster settlement and additional functionality.
The vulnerability allowed attackers to manipulate the sidechain's representation of Bitcoin and ultimately withdraw real BTC from its federation reserves.
This underscores the additional security assumptions users take on when moving Bitcoin into sidechains, bridges, custodial systems or other infrastructure layers.
For Bitcoin users, the incident reinforces a fundamental principle: the security of an application built around Bitcoin can differ significantly from the security of Bitcoin's base layer itself.
What Happens to the Remaining 598 BTC?
The immediate question is whether the actors will eventually return the remaining Bitcoin.
Blockstream has said it will continue working with law enforcement, exchanges, service providers and blockchain-forensics specialists to trace the funds and identify those responsible if the Bitcoin is not returned.
Meanwhile, Liquid is working toward restoring normal operations while ensuring that its BTC/L-BTC backing is properly restored.
The outcome could have implications beyond this individual incident.
If the remaining Bitcoin is recovered, the episode may ultimately serve as a major security lesson for Bitcoin sidechains and bridge infrastructure.
If it is not, the incident could become an important case study in the risks of large federated reserves and emergency negotiations following blockchain exploits.
Conclusion
Blockstream has drawn a firm line against paying a ransom for the remaining Bitcoin taken during the Liquid Network exploit.
Approximately 3,400 BTC has been returned, but nearly 598.5 BTC remains outstanding, leaving the dispute unresolved.
The incident also highlights a crucial distinction for Bitcoin investors: while Bitcoin's base layer remains operational, infrastructure built around it can introduce additional technical and custodial risks.
As Liquid continues its controlled recovery, the priority is restoring full network functionality, recovering the remaining funds and ensuring that the vulnerability cannot be exploited again.
For the broader Bitcoin ecosystem, the episode reinforces the importance of secure sidechain infrastructure, rigorous software validation and clear security-response procedures as Bitcoin's surrounding financial ecosystem continues to expand.