|
Getting your Trinity Audio player ready...
|
Blockstream is drawing a hard line with the hackers who drained hundreds of millions from its Bitcoin sidechain, and the message is blunt: this was theft, not a favor.
The company said Friday it will not meet a ransom demand from the attackers who exploited Liquid Network earlier this month, calling the framing of the incident as “responsible disclosure” a mischaracterization of what actually happened. Blockstream said taking funds without permission and holding them hostage is a crime, plain and simple — not the kind of security research the hackers claim it to be.
What the Hackers Wanted
According to an onchain message shared by Jan3 CEO Samson Mow, the attackers asked Blockstream to pay them a 10% bounty pulled from the company’s own funds. Their leverage was a threat: if Blockstream didn’t pay, Liquid users holding funds on the network would eat a 15% loss instead.
Blockstream says it tried working with the hackers in good faith to get user money back, but wouldn’t cave to the demand once it was made explicit. Instead, the company is calling on the attackers to hand back what’s left voluntarily. If that doesn’t happen, Blockstream says it’s prepared to bring in law enforcement, exchanges, and blockchain forensics teams to track the funds and identify who’s behind the exploit.
How We Got Here
The breach happened on September 6, when Liquid — a Bitcoin sidechain used for faster, more private transactions — was forced to pause operations after roughly 4,000 BTC, worth about $320 million at the time, was pulled from its federation wallet. The people responsible described themselves as white-hat hackers.
Most of the money has already come back. After Blockstream confirmed it had patched the vulnerable bridge nodes, the attackers returned 3,400 BTC, leaving about 598 BTC — worth tens of millions — still unaccounted for.
Liquid restarted block production on Thursday following emergency software updates, though the network is still running in a limited state. Blocks are currently empty, and both transactions and transfers in or out of the network remain frozen while the situation gets sorted out.
Also Read: White-Hat Hackers Return $270M in Bitcoin to Liquid Network After Patch Confirmation
What Comes Next
The standoff leaves Blockstream in a tricky spot: paying the ransom could recover the remaining funds quickly, but it would also validate a tactic the company insists is straightforward extortion. For now, Blockstream is betting that tracing tools and law enforcement pressure will get the same result without setting that precedent — even if it takes longer.
Disclaimer: The information in this article is for general purposes only and does not constitute financial advice. The author’s views are personal and may not reflect the views of Chain Affairs. Before making any investment decisions, you should always conduct your own research. Chain Affairs is not responsible for any financial losses.
I’m your translator between the financial Old World and the new frontier of crypto. After a career demystifying economics and markets, I enjoy elucidating crypto – from investment risks to earth-shaking potential. Let’s explore!

