
Key takeaways
- Blockstream refuses to pay for the remaining 598.5 BTC and describes the retention as theft, not responsible disclosure
- Blockstream says network operators were not hacked and federation keys were not compromised during the Liquid exploit
- The company says recovery work includes law enforcement, exchanges, service providers and independent forensic specialists
Blockstream refused to pay for the return of the remaining 598.5 BTC connected to the Liquid exploit. The company called keeping the bitcoin theft, not responsible disclosure. It said recovery work would continue with law enforcement, exchanges, service providers and independent forensic specialists.
Most of the bitcoin was returned
Reporting on the incident said roughly 3,400 BTC had already been returned after Blockstream patched the vulnerability. The remaining 598.5 BTC stayed withheld as the attacker demanded payment for its return. Blockstream rejected that demand and called the holdout theft.
Put the two numbers side by side (most came back, a chunk did not) and the dispute narrows to the remainder. About 3,400 BTC came back once Blockstream patched the vulnerability. The other 598.5 BTC did not come back, and Blockstream calls holding onto that 598.5 BTC theft rather than responsible disclosure.
Blockstream says federation keys stayed secure
Blockstream and Liquid said the network's federation operators were not hacked and federation private keys were not compromised. Their account located the incident in an exploited vulnerability, not a theft of the federation's signing keys. The company had patched that vulnerability before the reported return of roughly 3,400 BTC.
The order of events matters. Patching came first. The roughly 3,400 BTC return followed. That sequence, together with Blockstream and Liquid's statement that federation operators were not hacked and federation keys were not compromised, places the remaining 598.5 BTC dispute after remediation and outside any reported compromise of federation keys.
Recovery moved beyond direct negotiation
Blockstream said it was working with law enforcement, exchanges, service providers and independent forensic specialists to recover the remaining bitcoin. Its public position was that the 598.5 BTC should come back without payment. The company again called the holdout theft.
The refusal moved the dispute from a direct payment demand toward a coordinated recovery effort. Exchanges and service providers were part of Blockstream's stated recovery work, alongside law enforcement and independent forensic specialists, all aimed at the remaining 598.5 BTC.
Why It Matters
Roughly 3,400 BTC came back once the vulnerability was patched, but the remaining 598.5 BTC became the focus of a payment demand that Blockstream rejected. The company said federation operators were not hacked and private keys were not compromised. Both statements narrow the incident to the exploited vulnerability rather than a breach of the signing keys. Blockstream called the retained bitcoin theft and brought in law enforcement, exchanges, service providers and forensic specialists, treating the dispute as asset recovery rather than a paid disclosure process. That settlement now runs through law enforcement and forensic verification, not payment to the attacker.



















