On Friday, Blockstream drew a hard line. The company behind Liquid, Bitcoin’s most established sidechain, publicly rejected a demand from the group that drained nearly 4,000 BTC from the network last weekend. Roughly 598.5 BTC remains outstanding. The attackers want a 10% “bounty” paid from Blockstream’s own funds. Blockstream’s answer was clear: no.
The story began on September 6. Attackers exploited a subtle flaw in Elements, the open-source software that powers Liquid. A problem in how nodes cached range-proof verifications let them create thousands of unbacked L-BTC tokens. They then used a normal peg-out process through SideSwap, a federation member, to turn those tokens into real bitcoin from the federation’s reserve wallet. About $320 million left the reserve in a matter of hours. No private keys were stolen. The system simply accepted something that should never have been valid.
The group immediately labeled itself “white hats” in an on-chain message and offered to return most of the funds once the bug was fixed. Blockstream moved quickly. Bridge nodes were patched. On September 7, after the company confirmed the fix, the attackers sent back 3,400 BTC—roughly 85% of what they took. They kept the rest.
That is when the tone shifted. In a later message written in plain text on the blockchain, the group accused Blockstream of neglecting security, claimed the company had spent little or nothing to protect billions in assets, and issued an ultimatum: pay 10% of the total as a bug bounty out of corporate funds, or Liquid holders would absorb a permanent 15% loss. The language was blunt. They called the company delusional, greedy, and arrogant.
Blockstream’s response on September 11 left little room for interpretation. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure,” the company stated. “It is not white-hat activity. It is theft.” Officials said earlier contact with the group was made only in good faith to recover user funds. Accepting the demand, they argued, would set a dangerous precedent: that developers of open-source Bitcoin infrastructure can be forced to pay ransoms far beyond any reasonable economic stake.
The remaining 598.5 BTC—worth around $47 million at the time of the return—still sits in the attackers’ address. Blockstream has made clear that if the coins are not returned voluntarily, it will work with law enforcement, exchanges, service providers, and blockchain forensics teams to track the funds and identify those responsible.
Meanwhile, Liquid itself is partially back online. Block production and regular transactions resumed after an emergency software update. Peg-outs, however, remain disabled as a precaution while the reserve is restored. Some reports suggest Blockstream is prepared to cover any shortfall so that L-BTC continues to trade at a 1:1 ratio with bitcoin. That would protect ordinary users from the residual loss, even if the missing coins never come back.
The episode has reignited familiar debates. Where does responsible disclosure end and theft begin? How much risk should users accept when they move bitcoin onto a federated sidechain? And what does it mean for open-source developers when a vulnerability is discovered not through a formal bug-bounty program, but through an actual drain of hundreds of millions of dollars?
Liquid has always occupied a particular niche. It offers faster, confidential transactions while remaining anchored to bitcoin. That design depends on a federation of trusted parties and complex cryptographic software. The September 6 exploit showed how a single implementation flaw—in this case, a cache-key issue—can cascade into a six-figure-bitcoin event. The partial return of funds and the subsequent standoff only sharpened the questions.
Blockstream’s refusal to pay is consistent with a broader principle many in the Bitcoin community hold: do not reward theft, even when the thieves claim noble motives. Paying would effectively turn every serious vulnerability into a potential hostage situation. At the same time, the company faces practical pressure. Users want the peg restored and normal operations resumed. Covering the shortfall may be the cleanest way to achieve that, even if it means absorbing a loss the attackers still control.
As of now, the missing bitcoin has not moved. Liquid continues operating under restrictions. And Blockstream has publicly invited the remaining coins to come home—without a ransom attached. Whether the group accepts that invitation or forces a longer recovery process will determine the final chapter of this particular incident. For the moment, the message from Blockstream is simple and direct: return the bitcoin.
