Blockstream has rejected a 10% bounty demand from the group behind the Liquid Network exploit, insisting that the unauthorized removal of Bitcoin was theft rather than legitimate security research. The attackers have returned most of the stolen funds but still control roughly 598.5 BTC.
Blockstream has drawn a firm line in its dispute with the individuals who exploited the Liquid Network, refusing to pay a ransom for the return of the Bitcoin that remains outstanding.
Nearly 4,000 BTC was removed from Liquid-related reserves on September 6. The group responsible later returned 3,400 BTC, leaving approximately 598.5 BTC still unaccounted for.
The attackers have demanded a 10% bounty from Blockstream and warned that refusing their terms could result in Liquid users absorbing a larger loss.
Blockstream has rejected that proposal and said it is prepared to involve law enforcement, cryptocurrency exchanges and blockchain forensic specialists if the remaining Bitcoin is not returned.
Nearly 4,000 BTC Was Taken From Liquid
The incident began on September 6, when almost 4,000 BTC was withdrawn from reserves associated with the Liquid Network.
The individuals behind the transaction described themselves as “whitehats”, suggesting that the action was intended to expose a security weakness rather than conduct a conventional theft.
The situation quickly became more complicated.
The attackers began communicating with Blockstream through Bitcoin transactions containing OP_RETURN messages, effectively using the public blockchain as a channel for their negotiations.
After a series of communications, the group returned 3,400 BTC.
However, approximately 598.5 BTC remained in their possession, turning the recovery effort into a dispute over both compensation and responsibility.
Hackers Demand a 10% Bounty
Rather than returning the remaining Bitcoin without conditions, the attackers reportedly demanded a 10% bounty funded by Blockstream.
They also warned that failure to meet the demand could leave Liquid holders facing an estimated 15% loss.
That approach has become a major point of disagreement between the two sides.
Traditional white-hat security research generally involves identifying a vulnerability, reporting it to the affected organization and potentially receiving a reward through an established bug-bounty program.
Blockstream argues that removing assets without authorization and then withholding them while demanding payment does not fit that model.
The company said on September 11 that it would not pay a ransom for the return of stolen funds, maintaining that unauthorized asset removal followed by a demand for compensation constitutes theft rather than responsible disclosure.
Blockstream Rejects Passing Losses to Users
The dispute also raises a difficult question for Liquid users: who ultimately absorbs the shortfall if the remaining Bitcoin cannot be recovered?
Blockstream has rejected the idea that users should effectively fund the attackers’ demand.
The company has emphasized that Bitcoin cannot simply be created to compensate for missing funds. As a result, the unresolved 598.5 BTC represents a real financial gap that must be addressed through recovery, coverage or another solution.
Blockstream said its discussions with the attackers were conducted in an effort to recover users’ assets and should not be interpreted as acceptance of the group’s bounty conditions.
Previous Security Warnings Add to the Controversy
The incident has also triggered debate over whether Blockstream was warned about the vulnerability before the exploit occurred.
Calle, co-lead of Bitcoin Red Team, has claimed that his group previously alerted Blockstream to a security weakness.
The group later suggested that the incident demonstrated the consequences of failing to respond to those warnings.
Samson Mow, Blockstream’s former chief security officer, disputed the claim that warnings sent to the company were simply ignored.
The competing accounts have not been fully resolved.
Bitcoin Red Team has indicated that it plans to publish more information about the disclosure process after Blockstream releases its own postmortem.
That leaves two separate questions surrounding the incident: how the vulnerability became exploitable and how the remaining Bitcoin should be recovered.
Public Reaction Remains Divided
The dispute has generated sharply different reactions across the crypto community.
Some commentators argue that Blockstream should accept responsibility for the security failure and compensate the party that returned most of the stolen Bitcoin.
Others contend that returning part of the funds does not transform an unauthorized withdrawal into legitimate security research, particularly when a payment is being demanded for the remaining assets.
The debate also reflects a broader disagreement within cryptocurrency about responsibility for securing decentralized and blockchain-based infrastructure.
For Blockstream, the issue extends beyond the immediate financial loss. The company must also address questions about its security procedures, vulnerability disclosure practices and handling of the remaining funds.
Blockstream Prepares to Trace the Remaining Bitcoin
Blockstream has said that it will pursue other recovery options if the attackers refuse to return the approximately 598.5 BTC.
The company plans to work with law enforcement agencies, exchanges, service providers and blockchain forensic specialists to track the funds and attempt to identify those responsible.
Bitcoin’s public ledger could play an important role in that effort because transactions remain permanently recorded onchain.
While blockchain tracing does not automatically guarantee recovery, movements of the remaining Bitcoin can potentially be monitored as the funds move between addresses or interact with exchanges and other services.
Liquid’s Recovery Is Still Unfinished
The attackers have already returned the majority of the Bitcoin removed during the September 6 incident, but the unresolved balance remains substantial.
Key Figures
- Bitcoin initially taken: Nearly 4,000 BTC
- Bitcoin reportedly returned: 3,400 BTC
- Bitcoin still held by attackers: Approximately 598.5 BTC
- Bounty demanded: 10%
- Potential user loss warned by attackers: 15%
- Exploit date: September 6
The dispute has now moved beyond the question of whether a vulnerability existed.
It is also about whether unauthorized access to user assets can be characterized as white-hat activity and whether a security researcher can demand compensation after taking control of those assets.
Blockstream’s position is unequivocal: it will not pay the requested ransom.
The company’s message to the group holding the remaining Bitcoin is equally direct:

