Blockstream said Sept. 11 that it will not pay a ransom for bitcoin taken in the Liquid Network exploit. Liquid had reported on Sept. 8 that the actors returned 3,400 BTC, leaving about 598.5 BTC still outstanding as of 19:10 UTC that day.
In a statement, Blockstream said the unauthorized taking and continued withholding of the bitcoin was theft, not white-hat activity. The company said that if the funds are not returned, it will work with law enforcement, exchanges, service providers, and forensic specialists to trace the assets and identify those responsible.
Recovery for Liquid users is still not complete. The network resumed block production and transactions on Sept. 10, but peg-outs, the mechanism used to move bitcoin out of Liquid, remain disabled as a precaution while the recovery process continues.
Exploit created about 4,000 unbacked L-BTC
In its Sept. 8 incident report, Liquid said the Sept. 6 exploit created about 4,000 L-BTC that was not backed by bitcoin in the network reserve. The actors then used Liquid’s standard peg-out process to convert the unbacked L-BTC into BTC, releasing about 4,000 BTC.
The report said no private keys were compromised. Instead, the exploit targeted the way nodes running the open-source Elements software cached range-proof verifications. That caused the unbacked L-BTC to be accepted as valid before the peg-out was processed.
3,400 BTC returned, roughly 15% still outstanding
Liquid said the actors returned 3,400 BTC to the Liquid Federation peg wallet on Sept. 7. Its Sept. 8 accounting put the remaining amount at approximately 598.5 BTC, or 15% of the total.
The actors had left a message on the Bitcoin blockchain identifying themselves as white-hat security researchers and asking to be contacted about the vulnerability.
Blockstream rejected that claim. 「Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.」
The company also said its previous engagement with the actors was intended to recover user funds and should not be treated as acceptance of their actions or demands. It added that paying would set a precedent in which developers of open-source Bitcoin software could face ransom demands that exceed their economic participation.
Emergency patch released as peg-outs stay offline
Liquid announced on Sept. 9 that the emergency Elements v23.3.4 release was available and addressed the proof-verification cache vulnerability. According to Liquid’s latest operational update, transactions are running again, but peg-outs remain disabled pending the final stage of recovery.

