Blockstream has refused to pay a bounty demanded by an attacker who took bitcoin from the Liquid Network, even after 3,400 BTC was returned. The company calls the theft a crime, not a good-faith security disclosure.
Key Takeaways
- The incident involves an attacker who took funds from Blockstream’s Liquid Network.
- Reporting says 3,400 BTC was returned to a Liquid federation wallet.
- Blockstream then rejected the attacker’s demand for a bounty.
Blockstream is the company behind the Liquid Network, a “sidechain” (a separate blockchain linked to Bitcoin) built for faster, private transfers. Someone drained funds from it, then asked to be paid for giving them back. For related coverage, see UK Crypto Firms Get Five Months to Apply for FCA Approval.
On September 11, 2026, Blockstream said publicly that it would not pay, in a statement posted on X. The company described taking and withholding the assets as a crime, not responsible disclosure or “white-hat” work. For related coverage, see Standard Chartered Sees SKY Rising Fivefold by End-2028.
Here is the exact wording of that refusal, so you can read it directly rather than through a summary. For related coverage, see Circle’s EURC Euro Stablecoin Is Now Listed on Upbit.
To those responsible for the theft of bitcoin from the Liquid Network:
Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is…
— Blockstream (@Blockstream) September 11, 2026
Source: @Blockstream on X
We covered the early stage of this dispute in our earlier report on the Blockstream Liquid exploit and ransom demand. This article focuses on the refusal itself and what is still unconfirmed.
The return of 3,400 BTC preceded the rejection
Before the refusal, most of the missing coins came back. According to a September 11 report from crypto.news, 3,400 BTC was returned to the Liquid federation wallet on September 7, 2026.
BTC returned, as reported
3,400 BTC
The returned coins are not the whole story. crypto.news reports that nearly 4,000 BTC was withdrawn from the federation wallet on September 6, 2026. That figure is a reported approximation, not a transaction-by-transaction audit.
That leaves a gap. Both crypto.news and Unchained put the outstanding amount at roughly 598.5 BTC. The widely used “600 BTC” figure is rounded, not an exact observed balance.
BTC outstanding, as reported
Approximately 598.5 BTC
Importantly, the timeline established here is narrow. The return came before the refusal, but we cannot say exactly when the bounty demand was made or who controlled the receiving wallet.
How did the funds move in the first place? Unchained attributes to SideSwap, a Liquid trading service, the explanation that 4,000 L-BTC reached its peg-out service at 14:05 UTC, with roughly 4,000 BTC paid out 23 minutes later. SideSwap reportedly said its systems and its Peg-out Authorization Key were not compromised.
What remains unconfirmed about the bounty dispute
The core dispute is over what to call the attacker. A bounty demand from someone who took funds is not the same as an official bug bounty program, where a company invites researchers and agrees in advance to pay for disclosed flaws. No such agreement authorizing the attacker to keep coins has been publicly disclosed.
The demand itself is only partly documented. crypto.news reports that on-chain messages demanded a 10% bounty funded by Blockstream, though the original messages and the exact denominator were not independently verified. Some outlets have described a $50 million figure, but that number comes from a blocked report and, according to unconfirmed reports, cannot be treated as an established amount.
Industry voices are skeptical of the “white-hat” framing. Unchained reported that Ledger CTO Charles Guillemet questioned the label and said a negotiated reward involving the retained coins looked more like extortion. That is a paraphrase attributed to him, not a direct quote.
Blockstream also warned users about a second wave of risk. In its September 9 security notice, it said impersonators were posing as Liquid, Blockstream, and support staff. Scammers often follow a hack, hoping panicked users will click.
Here is the practical takeaway for regular holders. Blockstream said the incident does not require you to move funds, enter a recovery phrase, check a reimbursement, re-peg assets, or install software sent by email. Anyone asking you to do those things is likely a scammer, not the company.
This is the same pattern seen in other security scares, such as when Revolut faced fake official requests. The safest move is to ignore unsolicited messages and verify through official channels only.
Several key details still need verification: the precise reward demanded, the full reasoning behind Blockstream’s refusal, and the fate of the outstanding coins. Blockstream frames the taking and withholding as a crime and says it will work with law enforcement, exchanges, and forensic specialists, though no charges or named agency have been confirmed.
For context on the wider market, Bitcoin traded near $77,139 at the time of writing, little changed on the day. That price reflects current conditions and should not be read as a reaction to this incident.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.