Blockstream said it will not pay for the return of the roughly 598.5 BTC that remains with the group behind the Liquid Network exploit, rejecting the claim that the operation was white-hat security work. Withholding the coins “is a crime, not responsible disclosure,” the company said in a statement on X, adding that its earlier good-faith effort to negotiate their return should not be read as accepting the terms being demanded.

Submitting to the hackers’ demands of a 10% fee on the 4,000 BTC stolen would set a bad precedent for open-source software development, Blockstream said. The company said that if the remaining bitcoin is not returned voluntarily, it will work with law enforcement, exchanges, service providers and forensic specialists to trace the funds and apprehend the hackers.


This story is an excerpt from the Unchained Daily newsletter.

Subscribe here to get these updates in your email for free


That position leaves an unresolved hole in L-BTC‘s peg. Attackers drained about 4,000 BTC from a federation wallet holding roughly 4,200 BTC on Sept. 6, worth about $320 million at the time, then returned 3,400 BTC the following day once Blockstream confirmed its bridge nodes were patched. Neither Blockstream nor the Liquid Federation has said publicly who absorbs the remaining shortfall if the coins never come back.

Liquid said it resumed block production Thursday at 10:00 UTC, producing blocks without transactions while operators watch for stabilization. Functionary and bridge node updates have been deployed and functionary nodes are signing and validating blocks, the team said. Peg operations, including PAK-authorized peg-outs, remain suspended while the BTC-to-L-BTC reserve is restored, the team added.

Blockstream and Liquid have also warned users about a wave of impersonation attempts, including fake mandatory update portals, re-peg and claim sites, lookalike domains and unsolicited bounty outreach. The companies said they will never ask for a recovery phrase or PIN, request funds, or send software links by email. The exploit itself came from a flaw in Elements, the open-source software Liquid runs on, that let the attackers create L-BTC no bitcoin backed and redeem it through the network’s own withdrawal path.

Related Listen: I Went Undercover to Interview a North Korean Crypto Hacker