Breaking Crypto Whales Accumulate AAVE, UNI, and MOVR Heading Into October
Crypto Market News

Blockstream Tells Liquid Network Hackers It Won’t Pay Ransom for Remaining 598.5 BTC: ‘Return the Bitcoin’

By Mr Whale · September 13, 2026 · 3 min read
Share: X FB TG

“Return the bitcoin.”

That is the entire message Blockstream sent, on the record, to whoever is still holding roughly 598.5 BTC taken from its Liquid Network in a September 6 exploit. coin680 previously covered the initial breach and the bulk of the recovery; this is what happened after the money stopped coming back.

The attackers found a flaw in how Elements — the software underlying Liquid — cached the verification of range proofs, letting them mint close to 4,000 BTC worth of Liquid Bitcoin that had no real bitcoin backing it. They pushed that phantom L-BTC through SideSwap’s peg-out mechanism and walked away with genuine BTC from the Liquid Federation’s reserves, roughly $320 million at the time.

Then, unusually, they started talking. Through signed on-chain messages, the group told Blockstream they would send the funds back once the underlying bug was patched — and once Blockstream confirmed the fix, about 3,400 BTC came back within a day. That left 598.5 BTC, worth somewhere around $46 to $47 million, still in the attackers’ hands.

The tone shifted from there. A September 9 on-chain message accused Blockstream of spending “$1.5 million, maybe even 0” to secure roughly $5 billion in assets, and demanded a 10% bounty — effectively asking Blockstream to formally reward the theft in exchange for the rest of the funds, while warning of further consequences if refused.

Blockstream said no. On September 11, the company stated flatly that it will not pay a ransom for bitcoin taken in the exploit, characterizing the entire episode as theft rather than responsible security disclosure deserving of compensation. Its message to the attackers was blunt: return the bitcoin, or Blockstream will work with law enforcement, exchanges, service providers, and forensic investigators to trace the funds and identify who is responsible. SideSwap, whose infrastructure the attackers used to convert the stolen L-BTC into real BTC, put out its own statement backing Blockstream’s position, noting it has already handed over everything it has to help with tracing and has returned its own fee from the transaction.

Liquid itself remains in a cautious restart process. Block production resumed without processing new transactions as a precaution while Blockstream worked through an emergency software release, and the network’s peg mechanism is being brought back online in stages rather than all at once.

Bridge and sidechain exploits carry real financial risk, and recovery of stolen funds is never guaranteed even when negotiations are public. This article is for informational purposes only and is not financial advice.

Want to understand how bitcoin sidechains and federated bridges actually work — and where their trust assumptions can break down? Visit coin680’s Bitcoin Academy.


Share: X FB TG
Written by Mr Whale

Mr Whale has been active in the crypto market since 2020 and leads content and research at Coin680. More about our editorial team →

Get the Coin680 Daily Brief

Bitcoin news, market moves, and Academy lessons -- straight to your inbox, no spam.

Leave a Comment