Blockstream has refused to meet ransom terms set by attackers who still control funds taken from the Liquid Network, stating it will instead coordinate with law enforcement, exchanges and forensic analysts to trace the missing Bitcoin.
The company said on Friday that holding assets without permission and refusing to return them constitutes theft, not legitimate security research. Blockstream added that it had attempted to negotiate with the attackers in good faith but would not agree to their conditions.
In an onchain message posted Wednesday by Jan3 CEO Samson Mow, the attackers called for Blockstream to pay a 10% bounty using its own capital. They stated that Liquid users would otherwise lose 15% of their holdings.
Blockstream asked the attackers to send back the outstanding Bitcoin without further conditions. If they decline, the firm said it will pursue recovery through coordination with authorities, platform operators, service companies and tracing specialists to locate the assets and establish the identities of those involved.
The Liquid sidechain halted activity on Sept. 6 after attackers, describing themselves as white-hat operators, removed roughly 4,000 Bitcoin — valued at approximately $320 million at the time — from the federation wallet.
The group later returned 3,400 BTC once Blockstream confirmed that compromised bridge nodes had been secured, leaving around 598 BTC unaccounted for.
On Thursday, Liquid restarted block production and began generating empty blocks after emergency software patches were deployed. Transfers of Bitcoin in and out of the network, along with other transactions, remain disabled.
Source: cointelegraph.com