Blockstream has rejected a ransom demand for 598.5 Bitcoin following a September 6 exploit of the Liquid Network sidechain, accepting a structural shortfall in L-BTC backing rather than reward the attackers.

The exploit leveraged a vulnerability to mint approximately 4,000 L-BTC tokens without collateral, then used SideSwap's peg-out system to redeem them for real Bitcoin from the Liquid Federation's reserve wallet. Prior to the breach, that wallet held roughly 4,200 BTC ($320 million at the time). The attack drained approximately 95 percent of those holdings.

On September 7, attackers returned 3,400 BTC—85 percent of the stolen amount—but retained 598.5 BTC valued in the tens of millions. Blockstream stated it would not pay and characterized the actors as criminals, not white-hat researchers.

"We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation," the company said in a statement. Blockstream added it would pursue all available legal remedies and warned that blockchain transactions are permanently recorded.

Blockstream released Elements v23.3.4 to patch the vulnerability. Block production on Liquid has resumed and transactions are processing, though peg-out functionality remains disabled. The 598.5 BTC shortfall means L-BTC tokens are now backed only 85 percent by actual Bitcoin collateral.

Samson Mow, Blockstream's former chief strategy officer, provided updates on network stabilization but noted that full backing requires recovery of all stolen funds.