Blockstream has publicly refused to pay a ransom for the return of approximately 598.5 BTC stolen from the Liquid Network, declaring the funds stolen and threatening to involve law enforcement if the assets are not returned voluntarily. The company's stance comes as the federated sidechain has resumed limited operations following one of the largest exploits in Bitcoin-related infrastructure history.

The Liquid Network, a Bitcoin sidechain operated by a federation of exchanges and institutions, resumed block production on September 10 after deploying emergency software updates to address the vulnerability that enabled the attack. The exploit, which Decrypt reported as totaling approximately $47 million in stolen Bitcoin, had forced the network to halt operations while developers assessed the damage and implemented patches.

Despite the resumption of block production, the network remains severely constrained. Federation peg-outs—the mechanism allowing users to withdraw Bitcoin from the sidechain back to the mainchain—remain suspended according to CryptoSlate, leaving users unable to fully exit their positions. The publication noted that a September 10 on-chain snapshot placed reserve backing at just 85.15% of the total L-BTC supply in circulation, representing a significant deficit from the 1:1 backing the network is designed to maintain.

Blockstream's refusal to negotiate with the attackers marks a firm line in an increasingly common dilemma facing crypto infrastructure providers. The company characterized the ransom demand as illegitimate, with the reported position that the funds constitute theft rather than a situation warranting payment. This approach aligns with conventional cybersecurity wisdom that paying ransoms often encourages further attacks and provides no guarantee of asset recovery.

The timing of Blockstream's public statement coincides with the network's fragile restart. While block production has normalized, the suspension of peg operations and the 15% reserve shortfall indicate that full recovery remains distant. The federation structure of Liquid—where a consortium of functionaries controls the multi-signature contracts securing pegged Bitcoin—adds complexity to any recovery efforts, as coordination among members is required for significant protocol changes or reserve replenishment.

The market impact of the constrained withdrawal mechanisms has yet to be fully measured. CryptoSlate noted that live market depth for L-BTC remained unmeasured following the restart, leaving uncertainty about price discovery and liquidity conditions for the sidechain's native asset.

The incident represents a significant stress test for federated sidechain security models, which have historically been presented as more robust than purely centralized alternatives but less censorship-resistant than fully decentralized systems. The ability of an attacker to compromise sufficient federation members or infrastructure to extract nearly 600 BTC raises questions about the security assumptions underlying Liquid's architecture.

Blockstream's threat of legal action suggests the company may pursue the attackers through conventional law enforcement channels, a path that has seen mixed success in previous cryptocurrency thefts. The public blockchain nature of Bitcoin transactions provides permanent traceability, though the eventual recovery of stolen funds often depends on whether the attacker attempts to move assets through regulated exchanges or other identifiable touchpoints.