RUECAT DEX
All news
The Defiant 2h ago

Blockstream Rejects Ransom Demand Following Liquid Bitcoin Network Exploit

Blockstream refuses extortion terms from attackers who drained 4,000 BTC from Liquid, demanding the return of remaining funds.

Fortified cryptographic security shield symbolizing the rejected Blockstream Bitcoin ransom incident.

Bitcoin infrastructure firm Blockstream has taken a firm stand against cybercriminals following a major security incident on the Liquid Network, categorically rejecting a Blockstream Bitcoin ransom demand. The company demanded the immediate return of all remaining stolen digital assets after an exploit resulted in the unauthorized drainage of nearly 4,000 BTC from the sidechain.

Details published by The Defiant and Bitcoin.com News reveal that the perpetrators previously returned approximately 3,400 BTC while retaining a balance of roughly 598.5 BTC. The exploitation group framed the retained funds as a mandatory 10 percent bounty payment, warning that L-BTC sidechain holders could face a 15 percent haircut on their capital if the terms were rejected.

Blockstream dismissed the attackers' claims of acting as white-hat security researchers, labeling the unauthorized withdrawal an outright criminal theft. The firm explicitly confirmed that it will not negotiate ransom payments or sanction extortion tactics, drawing a strict line against incentivizing protocol exploits.

Following the incident, the Liquid Network resumed transaction processing to allow standard transfers, although peg-out mechanisms enabling users to bridge back to the Bitcoin base layer remained disabled. The network's federation members are working on remediation steps to protect user balances and restore full bridging functionality without validating the exploiters' ransom demands.

The standoff brings renewed attention to the security assumptions underlying federated sidechains and Bitcoin pegging architectures. While multi-signature federations are designed to secure cross-chain assets, systemic exploits test the economic and legal resilience of network custodians when large pools of capital are breached.

Investigators and forensic analysts are now tracking the movement of the outstanding 598.5 BTC across public blockchain ledgers. Market participants await further technical disclosures from Blockstream regarding how the vulnerability was accessed and the definitive timeline for restoring full peg-out operations.

Key takeaways

  • Blockstream rejected a ransom demand from hackers who stole nearly 4,000 BTC from Liquid Network.
  • The attackers returned 3,400 BTC but retained roughly 598.5 BTC as an unauthorized bounty.
  • Liquid transactions have resumed, but peg-out functionality remains temporarily disabled.