A massive hack has struck Blockstream‘s Liquid Network. 598.5 BTC — worth approximately $47 million — remains in the hands of the attackers. Faced with a ransom demand, the company has adopted a firm, uncompromising stance.
Blockstream has publicly described the incident as “plain theft” and categorically refuses any financial negotiation with those responsible for the attack. A clear line has been drawn, with legal consequences announced should the funds not be returned.
Behind this incident lies a far broader issue: the credibility of Bitcoin sidechains in the face of increasingly sophisticated attack vectors targeting decentralized finance infrastructure.
598.5 BTC at Stake: What We Know About the Liquid Network Hack
Liquid Network is a Bitcoin sidechain developed by Blockstream, designed to enable fast and confidential transactions between exchanges and institutions. It relies on a multi-signature federation mechanism, intended to guarantee the security of funds locked within the protocol.
The attack allowed hackers to seize 598.5 BTC, a substantial sum representing a significant portion of the network’s total liquidity. The precise technical details of the exploit have not yet been fully disclosed by Blockstream — a common practice aimed at avoiding providing a blueprint for copycat attacks. That partial silence has nonetheless fueled community concerns about the real robustness of the federated model.
The attackers subsequently contacted Blockstream to demand a ransom in exchange for returning the funds. An extortion attempt that clearly found no receptive audience among the company’s leadership.
“It’s Theft”: Blockstream Takes a Hard Line and Threatens Legal Action
Blockstream‘s response leaves no room for ambiguity. The company refuses any transaction with the hackers and explicitly labels their actions as “theft” — a deliberate framing that places the matter firmly in criminal territory rather than on the negotiating table.
Blockstream has announced it will refer the case to law enforcement if the 598.5 BTC are not returned. This stance reflects a broader trend emerging across the industry: after years in which hack victims preferred to negotiate quietly in order to limit losses, several major players are now choosing the legal route to send a clear deterrent signal.
This approach does, however, come with practical limitations. Tracing and recovering Bitcoin moved by sophisticated actors remains an enormous challenge, even for specialized agencies such as the FBI or Europol. On-chain analytics tools like Chainalysis and Elliptic can identify fund flows, but conversion through mixers or cross-chain bridges often makes definitive attribution extremely difficult.
Liquid Network Under Pressure: What Future for Bitcoin Sidechains?
This incident comes at a time when sidechains and Bitcoin Layer 2 solutions are attracting growing interest, particularly following the rise of Ordinals, BRC-20 tokens, and DeFi projects built on Bitcoin. Liquid Network positions itself as a serious institutional infrastructure — making this hack a direct blow to its core value proposition.
The central question is that of the attack surface inherent to federated models. Unlike Ethereum smart contracts that are publicly auditable, the internal mechanics of a multi-sig federation can conceal vulnerabilities that are far less visible. Exchanges and institutions using Liquid for fast settlements will inevitably be reassessing their exposure.
For Blockstream, the stakes go well beyond recovering the funds: the company must demonstrate that its crisis response — transparency, refusal to yield to extortion, and recourse to legal authorities — itself constitutes a standard of responsible governance in a sector still too often defined by opacity in the aftermath of incidents.