Blockstream Says NO to Liquid Ransom Demand — But the Bigger Question Is Still Open.

The Liquid Network exploit has taken another turn.

Blockstream has now made its position clear: it will not pay a ransom to the attackers holding the remaining Bitcoin from the incident.

The controversy began after roughly 4,000 BTC—worth around $320 million at the time—was withdrawn from Liquid’s federation wallet. The attackers described themselves as “white hats” and later returned approximately 3,400 BTC after the underlying vulnerability was addressed. Around 600 BTC remains outstanding.

Now the attackers are demanding compensation for what they describe as responsible security research. Blockstream rejects that argument.

The company says taking assets without authorization and then withholding them is theft, not responsible disclosure. It also says it will work with law enforcement, exchanges, service providers and forensic specialists to trace and recover the remaining funds if they are not returned.

But here is the part I find most important:

This is no longer just a “hack” story. It is a trust and security-design test.

A vulnerability was serious enough to allow unbacked Liquid Bitcoin to be converted into real BTC, while the cryptographic federation keys themselves were reportedly not compromised.

That distinction matters.

The next phase will show whether Liquid can restore confidence through stronger validation, deeper security review and transparent communication—not simply by recovering the missing coins.

For crypto infrastructure, security isn't proven when everything works.

It is proven when the system is attacked.

Do you think the remaining BTC should be returned with zero bounty, or should legitimate vulnerability discovery still receive compensation?

#BTC $BTC

BTC
BTC
77,325.61
+0.55%