Blockstream announced it will not pay a ransom for the return of 598.5 BTC (about $47 million) still held by attackers after the exploit of its Liquid Network sidechain. The company called withholding the funds a straightforward crime, not an act of "responsible disclosure."
The total amount drained from the network on Sunday reached about 4,000 BTC, or $320 million at the time. It is one of the largest incidents around Bitcoin infrastructure in the past year, and the way Blockstream shaped its response sets a precedent for dozens of similar sidechains and bridges across the market.
Incidents like this affect more than developers: anyone holding assets in bridges, sidechains, or custodial services does not physically control their funds the moment a breach happens, and the team's response speed becomes the only real defense.
Hackers took 4,000 BTC, returned 85% of it
The attack on the Bitcoin sidechain Liquid happened on Sunday morning. Attackers drained roughly 4,000 BTC from the network in a single stream of transactions, exploiting a flaw in the bridge nodes. On Monday they returned 3,400 BTC, or 85% of the stolen amount, keeping 598.5 BTC at the address they withdrew to. That address has not moved since the attack and remains under close watch by analysts.
The motive behind the partial return is simple: the hackers wanted negotiation, not an outright escape with the full amount. In a message embedded in a Bitcoin transaction, they described their actions as a paid vulnerability search rather than theft. Blockstream did not accept that framing.
A flaw in Liquid's code let attackers mint unbacked L-BTC
The root cause was a bug in how Liquid nodes cached range proof verification, the cryptographic check that confirms a transaction amount is correct. Attackers exploited this to mint unbacked L-BTC, the wrapped version of Bitcoin inside the Liquid network, then swapped those tokens for real BTC through SideSwap, a federation member holding a peg-out authorization key.
The network's reserve dropped to 197 BTC as a result. For a network that held more than $5 billion in assets at the time of the attack, that is a critically thin backing. Liquid has no single centralized issuer, so a breach at one node bypasses the safeguards of the whole system at once.
Federated bridges like Liquid chose this architecture for faster, cheaper transfers compared with Bitcoin's base layer. The tradeoff is less decentralization: the network is only as reliable as its weakest federation member.
A patch in 10 hours and the network back online
Blockstream closed the vulnerability in the bridge nodes within 10 hours of discovery, a fast turnaround for an infrastructure bug of this scale. On Wednesday, the company shipped the Elements v23.3.4 update with the fix and pushed it to every node operator on the network.
On Thursday, Liquid resumed producing blocks and processing transactions, though converting L-BTC back into regular BTC remains disabled as a precaution during the final stage of recovery. Separately, the company warned node operators about phishing sites disguised as software update pages that try to steal access keys.
For ordinary L-BTC holders, this comes down to one simple point: until peg-outs are restored, no exchange or exchanger accepting the asset can guarantee an instant exit into regular BTC.
A 10% "bounty" demand and Blockstream's flat refusal
In an on-chain Bitcoin transaction on Wednesday, the attackers wrote that Blockstream had allocated "only $1.5M to secure $5B assets," calling it outright negligence. They demanded 10% of the amount as a reward for finding the flaw, or promised token holders a 15% loss otherwise.
On Friday, Blockstream answered directly: the company will not pay a ransom for stolen funds and will not call this "white-hat activity." Its statement said taking assets without authorization and withholding their return is a crime, not the ethical work of a security researcher. The company also refused to cover the shortfall from ordinary network users.
"Bitcoin is hard money and can't be minted without costs. Bitcoin doesn't haircut users to pay a ransom."
- Blockstream, public statement, September 11, 2026
This has happened before: from Poly Network to Ronin
Partial fund returns in exchange for a "white-hat" label are not new. In 2021, the Poly Network hacker drained $611 million, then returned nearly all of it after public pressure and negotiation. In 2022, the attackers behind the Ronin Network breach took $625 million and never returned a single token, despite years of investigation.
The Wormhole bridge was hit in 2022 as well: an attacker drained $325 million, and investment firm Jump Crypto later covered the loss out of its own funds to preserve the Solana community's trust in the network.
Blockstream deliberately chose a stance closer to Ronin than to Poly Network: no concessions, and no acknowledgment of negotiation as a form of settlement. For the bridge industry, that is a signal that companies are increasingly rejecting quiet deals with attackers, even after part of the funds has already come back.
Risks for other sidechains and bridges
The Liquid model runs on a federation, a small group of functionary members holding the keys for moving funds in and out. The attack showed that compromising even one such member opens access to the network's entire reserve.
Historically, attacks on bridges and federated systems top the list of the most expensive breaches in the crypto industry, so the Liquid incident falls into a category the industry already knows all too well.
- A single point of trust: the peg-out key belonged to one federation member, SideSwap, and the swap of forged tokens for real BTC ran through exactly that member.
- Blockstream's refusal to pay could become a reference point for other projects facing similar demands after a breach.
- While L-BTC withdrawals stay disabled, token holders cannot convert their assets back into regular BTC, and that pause has already lasted several days.
- Phishing sites posing as node update pages show attackers trying to profit twice: once from the breach itself, and once from the panic around it.
- Anyone holding funds on similar platforms should check only official project channels, not third-party links, especially right after an incident.
The episode underlined the difference between holding assets in your own wallet and trusting someone else's infrastructure: the first depends only on whoever controls the keys, the second, as Liquid showed, depends on the federation's weakest link.
The market reaction was muted. The rate at which traders can exchange Bitcoin for dollars swung between $76,600 and $80,300 over the week, and BTC was trading around $78,592 as of Friday. The same week brought US core CPI data showing a faster-than-forecast 0.3% rise, while bitcoin ETFs logged a net outflow of $449 million over three trading days, adding to market jitters. Blockstream said it would pursue "every lawful avenue" through law enforcement, exchanges, and forensic specialists if the rest of the funds are not returned. For now, 598.5 BTC sits frozen at a single address, and whether it can be recovered through legal channels will decide how tempting the "keep part of it and demand a reward" playbook becomes for future attacks on similar bridges.




Comments
Your email address will not be published. Required fields are marked *