Blockstream has refused to pay a ransom for the return of bitcoin stolen from its Liquid Network, telling those responsible in a public statement on September 11, 2026 to simply “Return the bitcoin” as roughly 600 BTC remained outstanding from the exploit.
The refusal was posted directly by Blockstream on X, where the company said it would not pay for the return of stolen funds. For Southeast Asian holders of L-BTC and traders who route liquidity through Liquid-connected venues, the standoff is a live reminder of how quickly a sidechain incident can freeze access to funds. For related coverage, see PolyNext Awards & Conference Dubai 2026: Advancing the Global Dialogue on Plastic Recycling and Circularity.
Blockstream refuses the reported Liquid exploit ransom demand
What Blockstream said about its response
Blockstream stated that taking assets without authorization and withholding their return is a crime, not responsible disclosure, and not white-hat activity. The company framed the act as theft rather than a bug bounty situation. For related coverage, see Ethereum Above $2,600: Can ETH Reach $3,000?.
It added that its earlier engagement to recover user funds was done in good faith and did not constitute acceptance of the demanded terms. Blockstream said that if the funds were not returned, it would work with law enforcement, exchanges, service providers and forensic specialists to trace and recover them and identify those responsible. The statement closes with the words “Return the bitcoin.”
The exact wording and speaker are confirmed by the official post itself. Below is Blockstream’s statement as published on X.
To those responsible for the theft of bitcoin from the Liquid Network:
Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is…
— Blockstream (@Blockstream) September 11, 2026
Source: @Blockstream on X
What the remaining 600 BTC figure tells us
Remaining funds versus total losses
The 600 BTC in question is a remaining balance, not the full amount involved in the incident. Cointelegraph reported that Liquid paused operations on September 6 after approximately 4,000 BTC was withdrawn from its federation wallet, a figure Unchained independently reported on the same date.
The actors then returned 3,400 BTC after Blockstream said affected bridge nodes had been patched, according to both Cointelegraph and Unchained. That leaves the outstanding balance in dispute; Unchained put it at roughly 598.5 BTC, which the headline rounds to 600. No explorer-based current balance has been independently verified. Our earlier coverage tracked how Blockstream rejected the ransom as hackers held nearly 600 BTC.
Both outlets reported a demand for a 10% bounty or fee, which Cointelegraph attributed to an onchain message shared by Blockstream co-founder Samson Mow; the underlying transaction was not independently inspected. According to unconfirmed reports cited by Cointelegraph, the attackers also threatened a 15% loss for Liquid holders unless paid, a claim that is not an established or agreed customer haircut. No dollar conversion is applied here because incident-time valuation was not established.
What remains unverified about the Liquid exploit report
Incident details and recovery status
Key parts of the incident remain unconfirmed. Unchained reported that an Elements flaw allowed unbacked L-BTC creation and redemption through Liquid withdrawals, but no official technical postmortem, exploit transaction or patch analysis has been published. That root cause should be treated as an unverified single-source claim until Blockstream confirms it.
The current operating status is also unsettled. Fetched reporting described an earlier empty-block restart with transactions or peg operations suspended, while unconfirmed reports suggest transactions later resumed with peg-outs still disabled. The supplied evidence does not establish the present location or recovery status of the outstanding coins.
Blockstream’s stated intent to pursue lawful recovery is a plan, not proof that a case, court order or enforcement action has begun. This matters for regional oversight: no ASEAN regulatory response has been verified, and there is no substantiated evidence of exposure at local venues.
What ASEAN exchanges and holders should watch
On September 9, Blockstream warned of impersonators using fake mandatory updates, reimbursement or re-peg claims, unsolicited DMs and lookalike domains following the incident, in an official phishing alert. The company said the incident does not require users to move funds, disclose a recovery phrase, re-peg assets or install emailed software, and that it would never request a recovery phrase or PIN.
That guidance is directly relevant to users across Jakarta, Bangkok, Manila and Singapore, where phishing campaigns often follow global security incidents. As with other recovery-linked scams such as the NES recovery and refund eligibility process, regional holders should verify any re-peg or reimbursement message against official channels before acting.
Bitcoin traded at around $77,137 at the time of research, down about 0.22% over 24 hours, and no incident-specific price impact has been verified. Broader appetite stayed firm, with sentiment such as macro signals like sticky CPI shaping Bitcoin’s upside continuing to dominate market attention rather than the Liquid dispute. For now, no confirmed haircut and no verified regional loss have emerged, and the next official Blockstream update will determine whether the outstanding coins are recovered or written down.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
