Blockstream announced it will not pay a ransom for approximately $47 million in Bitcoin still held by attackers following an exploit on the Liquid Network. The company stated that withholding assets without authorization constitutes theft rather than responsible disclosure or white-hat activity. This decision follows the return of 3,400 BTC, representing about 85% of the total amount drained during the incident.
The attack exploited a flaw in how Liquid nodes cache range proof verifications, allowing hackers to mint unbacked L-BTC and swap it for reserve Bitcoin via SideSwap. Blockstream patched the bridge nodes within ten hours and released Elements v23.3.4 to restore network functionality, though peg-outs remain disabled as a precaution. The firm plans to work with law enforcement, exchanges, and forensic specialists to trace the remaining funds, emphasizing that blockchain transactions leave permanent evidence.
This refusal establishes a critical boundary for open-source infrastructure providers facing extortion attempts. By rejecting the demand for a bug bounty disguised as a ransom, Blockstream avoids setting a precedent where developers are financially coerced into paying sums disproportionate to their economic participation. The stance reinforces the principle that unauthorized asset retention is criminal conduct, distinct from ethical security research.
From a market structure perspective, the incident highlights vulnerabilities in sidechain peg mechanisms and the operational risks associated with federation members holding authorization keys. While the rapid patching and partial fund recovery demonstrate technical resilience, the lingering threat to the remaining 598.5 BTC underscores the importance of robust node verification protocols. Stakeholders should monitor whether this hardline approach influences future negotiations between crypto firms and malicious actors, potentially shifting industry norms away from silent payments toward transparent legal recourse.


