Blockstream announced Sept. 11 it will not pay a ransom to recover approximately 598.5 Bitcoin still held by hackers who exploited the Liquid Network. The Bitcoin infrastructure company characterized the unauthorized taking of assets as theft, rejecting the actors' demands for payment.

Liquid, a Bitcoin sidechain, initially paused operations Sept. 6 after self-described "white-hat" hackers withdrew about 4,000 BTC from its federation wallet, valued at approximately $320 million at the time of the exploit. Following emergency patching of affected bridge nodes, the actors returned 3,400 BTC, leaving 598.5 BTC outstanding. At current market rates, the remaining amount is valued at approximately $47 million.

The hackers communicated their demands via an on-chain message shared publicly Wednesday by Samson Mow, former Blockstream chief strategy officer and Jan3 CEO. They requested a 10 percent bounty from Blockstream's own funds, warning that Liquid holders would otherwise face a 15 percent loss on their assets.

Blockstream rejected these terms, stating that taking assets without authorization and withholding their return constitutes a crime, not responsible disclosure or white-hat activity. The company confirmed it had engaged with the hackers in good faith to secure user fund recovery but would not acquiesce to their demands.

Blockstream urged the hackers to voluntarily return the remaining Bitcoin. If the funds are not returned, the company stated its intention to collaborate with law enforcement, cryptocurrency exchanges, service providers, and forensic specialists to trace the assets on-chain and identify those responsible.

Liquid resumed block production Sept. 10 following emergency software updates, but the sidechain is currently producing empty blocks. All transactions, including Bitcoin transfers into and out of the network, remain suspended, impacting the network's utility for faster BTC settlements.

The exploit targeted the multi-signature federation wallet securing the sidechain, exposing vulnerabilities in centralized points of control within sidechains. The reliance on a specific set of functionaries for asset custody means that compromise of these nodes can lead to significant capital outflows and network disruption.