Blockstream Declines Ransom Demand After Liquid Network Security Breach
Blockstream Stands Firm, Rejects Ransom After 598 Bitcoin Lost in Liquid Network Hack
James Thorp · September 13, 2026
Blockstream won’t pay. Full stop. After hackers drained nearly the entire federation wallet on its Liquid Network sidechain, the company got most of it back — but 598 Bitcoin are still gone, and the ransom demand sitting in its inbox isn’t getting answered.
The breach started September 6. Self-described white-hat hackers exploited Liquid, Blockstream’s Bitcoin sidechain, and pulled roughly 4,000 Bitcoin out of the federation wallet. At the time, that haul was worth around $320 million. The wallet held about 4,200 Bitcoin before the attack — so the hackers basically cleaned it out.
Blockstream scrambled, pushed emergency software patches to affected bridge nodes, and managed to claw back 3,400 Bitcoin. But 598 Bitcoin never came back. That leaves the network 85% collateralized, sitting in an awkward limbo where block production has resumed but peg-outs — the mechanism that lets users move Bitcoin in and out of the network — are still disabled. You can transact. You just can’t exit.
598 Bitcoin. Still missing. No timeline.
The Ransom Demand and Blockstream’s Answer
The hackers didn’t disappear quietly. They sent an on-chain message — the kind of move that’s become almost theatrical in crypto security incidents — warning that Liquid holders could face a 15% loss if Blockstream didn’t hand over a 10% bounty. Not from recovered funds. From Blockstream’s own money.
Jan3 CEO Samson Mow shared that message publicly, which is probably how most people found out about the demand in the first place. Blockstream’s answer was no. The company called it theft, not responsible disclosure — a pretty important distinction in the world of bug bounties and white-hat hacking, where the difference between a payout and a prosecution often comes down to whether you returned the funds first and asked questions later.
Blockstream’s framing makes clear it sees this as extortion dressed up in security researcher language. And it won’t budge. The company said it’s engaging with law enforcement and forensic specialists to track the missing Bitcoin and figure out who’s behind the


The Currency Analytics