Why Is Blockstream Refusing to Pay the Exploiter?
Blockstream has rejected a demand for a 10% bounty from those responsible for the Liquid Network exploit, saying it will not pay for the return of the remaining 598.5 BTC while warning that recovery efforts could now involve law enforcement, exchanges and blockchain forensic specialists.
“Return the bitcoin,” Blockstream said Friday after efforts to secure the remaining funds failed to produce an agreement.
The company said it had attempted to recover the assets in good faith but rejected the terms being demanded by the exploiter. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure,” Blockstream said. “It is not white-hat activity. It is theft.”
Blockstream also argued that paying the requested bounty would create an unacceptable precedent for developers of open-source Bitcoin software, particularly where the demanded payment substantially exceeds their direct economic participation in the affected system.
The company said the attacker still has an opportunity to return the funds voluntarily. If that does not happen, Blockstream said it intends to work with law enforcement agencies, exchanges, service providers and forensic firms to trace the assets and identify those responsible.
“We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds,” the company said.
How Did the Liquid Exploit Create Unbacked LBTC?
The incident stemmed from a vulnerability involving the caching of range-proof verifications in Elements, the software underlying the Liquid Network. The flaw allowed approximately 4,000 LBTC to be created without corresponding bitcoin being held in reserve.
The exploiter then used SideSwap, a Liquid Network wallet and trading platform that holds a peg-out authorization key as a Liquid Federation member, to convert the unbacked LBTC into BTC through a standard peg-out process.
Liquid said its network operators were not compromised and that no private keys were stolen. The failure instead occurred at the software-validation level, making the incident particularly important for a network whose LBTC asset is intended to remain backed one-for-one by bitcoin.
On Sept. 7, the exploiter returned roughly 3,400 BTC after previously sending an onchain message instructing Blockstream to “fix the bug first.” About 598.5 BTC remained outstanding after that transfer.
Investor Takeaway
The main risk has shifted from stopping the exploit to restoring full backing and normal network operations. Liquid can resume transaction processing, but unresolved losses and disabled peg-outs leave the recovery incomplete until the reserve gap is addressed.
Why Are Liquid Peg-Outs Still Disabled?
Liquid has made substantial progress in restoring the network. Elements version 23.3.4 was deployed on Sept. 9, block production resumed on Sept. 10 and ordinary transactions were subsequently re-enabled later the same day.
Peg-outs remain disabled, however, while operators work through the final stage of recovery and restore the relationship between BTC held in reserve and outstanding LBTC.
The restriction limits users’ ability to move bitcoin out of the federation-controlled system even though transactions within Liquid have restarted. Keeping peg-outs suspended reduces the risk of further reserve pressure while operators verify network stability and address the remaining shortfall.
The exploit therefore remains economically relevant even after most of the bitcoin was returned. Liquid’s core design depends on confidence that circulating LBTC can ultimately be redeemed against bitcoin reserves, making restoration of the backing ratio more important than simply restarting block production.
What Happens to the Remaining 598.5 BTC?
The dispute now centers on whether the exploiter returns the remaining bitcoin without compensation. In an OP_RETURN message sent Wednesday, the attacker demanded a 10% bounty and criticized Blockstream’s security spending, arguing that the company should fund the payment itself.
Blockstream has now rejected that demand explicitly, turning the remaining recovery into a tracing and enforcement issue rather than a bounty negotiation.
The outcome could matter beyond Liquid. Paying unusually large rewards after unauthorized asset creation could encourage attackers to frame economically damaging exploits as retrospective bug-bounty negotiations. Refusing payment, however, increases the risk that the remaining funds stay outside the reserve while recovery efforts continue.
For Liquid users, the immediate question is when peg-outs can safely resume. For Blockstream, the larger issue is whether the network can restore full reserve coverage without rewarding the party responsible for creating and extracting the unbacked assets.

