Skip to main content

Blockstream Refuses to Pay Ransom, Liquid Hacker Still Holds Nearly 600 BTC; Revolut User Data Breach Explained

tutorial By

Blockstream refused to pay a ransom while the Liquid hacker held about 598 BTC, and Revolut leaked user passports and transaction data; learn OKX safety steps.

深海军蓝财经编辑封面:抽象安全主题视觉,以盾牌轮廓、链上节点与碎片化数据卡片组合为单一焦点,绿色高光点缀,留下干净负空间,不含任何文字、Logo 或人物
AI 生成示意图,不代表真实事件现场。
✓

Article Citation Summary

Updated: 2026-09-13 Source: OKX Radar

Blockstream refused to pay a ransom while the Liquid hacker held about 598 BTC, and Revolut leaked user passports and transaction data; learn OKX safety steps.

Core Summary: As of public reports on September 12, 2026, Blockstream refused to pay a 10% bounty to the Liquid network hacker, who still holds about 598 BTC; Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests. For OKX users, the focus is not just watching the events but immediately checking account security settings, enabling two-factor authentication, setting up withdrawal whitelists, and staying vigilant against phishing requests impersonating officials.

Incident Review: Blockstream Refuses to Pay Ransom and the Liquid Hacker's 598 BTC

信息图:以图形流程总结 Blockstream 拒付赎金与 Revolut 数据泄露两大风险源,指向 OKX 用户三项防护行动(双重认证、提现白名单、防钓鱼),仅使用两个英文短标签,无中文文字

What did the hacker demand?

According to a Cointelegraph report on September 11, 2026, the hacker withdrew approximately 4,000 bitcoins (worth about $320 million at the time) from the Liquid alliance wallet, then returned 3,400, leaving about 598 unreturned. The hacker demanded that Blockstream pay a 10% bounty from its own funds, otherwise Liquid holders would face a 15% loss.

Why did Blockstream refuse?

Blockstream refused to pay the ransom and condemned the hacker's actions as theft rather than white-hat activity. This stance indicates the platform is unwilling to provide positive incentives for attacks, but Liquid users still need to monitor subsequent asset return progress. The facts in this section come solely from the Cointelegraph report and may continue to update.

Revolut User Data Breach: How Passports and Bitcoin Transaction History Were Tricked Out by Fake Government Requests

What was the scope and type of leak?

According to a Decrypt report on September 12, 2026, Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests. The leaked information at least includes passport data and Bitcoin transaction history, which is highly sensitive personal data.

What risks do users face?

Such data breaches may lead to targeted phishing, identity impersonation, and asset-targeting attacks. Attackers can combine passport information with transaction history to craft more deceptive official notices or customer service contacts. Although OKX users are not involved in this incident, they should be wary of similar social engineering tactics.

What It Means for OKX Users: Mapping and Self-Check of Similar Risks

Comparison of Key Facts in the Two Incidents

Incident Key Facts Main Risks Implications for OKX Users
Blockstream refuses to pay ransom Hacker withdrew about 4,000 BTC, returned 3,400, still holds about 598; Blockstream refused to pay 10% bounty Liquid holders may face asset loss; platform does not reward attacks Monitor custodian security, avoid transfers induced by social engineering
Revolut user data breach Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests Targeted phishing, identity impersonation, asset-targeting attacks Protect personal identity information and transaction privacy, beware of fake customer service

What similar risks might my OKX account face?

The common points of the two incidents are social engineering, impersonating officials, and custodian attacks. Although OKX users are not involved in these incidents, they cannot relax their vigilance. Attackers may use similar leaked data to impersonate OKX customer service or regulatory agencies, tricking users into giving up passwords, 2FA codes, or API keys.

How to determine if you are affected?

Users should check login devices, API keys, withdrawal address lists, and recent activity records on their OKX account. Any urgent notification claiming to be from OKX or request for passwords or verification codes should be re-confirmed through official channels. Specific verification paths should refer to the latest instructions in the OKX official App or website help center.

Actionable Protection Steps: An OKX Security Checklist Distilled from the Two Incidents

How to enable two-factor authentication?

  1. Log in to the OKX official App or website and go to the account security or security center page.
  2. Find the two-factor authentication (2FA) option and choose a time-based one-time password (TOTP) or hardware key.
  3. Follow the prompts to bind the authenticator and save the recovery code to complete activation.

How to set up a withdrawal whitelist?

  1. Find the withdrawal whitelist function in security or withdrawal settings.
  2. Add pre-confirmed withdrawal addresses and enable whitelist restrictions so assets can only be transferred to confirmed addresses.

How to identify fake requests?

  1. Do not click unknown links, and do not disclose passwords, 2FA codes, or API keys to anyone.
  2. Contact the platform through the built-in customer service channel in the OKX official App or website, and do not trust customer service numbers from search engine ads or unfamiliar emails.
  3. Regularly check account activity, device lists, and API permissions, and promptly remove authorizations that are no longer used.

OKX Security Self-Check Checklist

Category Specific Action Purpose
Two-factor authentication Log in to OKX official App or website, go to security center, enable TOTP or hardware key Prevent unauthorized account login
Withdrawal whitelist Add pre-confirmed addresses in withdrawal settings, enable whitelist restrictions Assets can only be transferred to confirmed addresses
Fake request identification Do not click unknown links, do not disclose password/2FA/API keys, confirm through official built-in customer service Prevent phishing and social engineering
Regular self-check Check login devices, API keys, withdrawal addresses, activity records, remove unused authorizations Detect anomalies and stop losses in time

The above steps are based on general security practices and outline requirements. Specific feature names and operation paths should refer to OKX's latest official documentation.

FAQ and Risk Disclaimer

What is the latest progress on these incidents?

As of September 12, 2026, public reports show the Liquid hacker still holds about 598 BTC, and the Revolut breach has been exposed. For subsequent progress, please check primary sources such as Cointelegraph and Decrypt; this article does not replace real-time verification.

How does OKX Radar verify information?

As an independent third-party media, OKX Radar only provides incident interpretation and security education based on public sources, and does not provide trading or legal advice. All security operation suggestions in this article should be based on OKX's latest official documentation, and users should assess applicability on their own.

Risk Disclaimer: Crypto/digital asset prices are highly volatile, and materials and rules may change at any time. This article does not constitute investment, legal, or tax advice. Before making decisions, refer to the latest official announcements and actual product pages.

References and verification links

These are the article-level sources stored with this page. Interpret dynamic facts and rules in light of their dates, regions, and subsequent updates.

  1. Blockstream rejects ransom as Liquid hackers return Bitcoin
  2. Revolut exposed passports and Bitcoin activity in data breach

FAQ

Why did Blockstream refuse to pay the ransom? ▼

Blockstream refused to pay a 10% bounty to the Liquid network hacker and condemned the hacker's actions as theft rather than white-hat activity. This stance comes from a Cointelegraph report on September 11, 2026, and may be updated later.

How much BTC does the Liquid hacker still hold now? ▼

As of the Cointelegraph report on September 11, 2026, the Liquid hacker withdrew about 4,000 BTC and returned 3,400, still holding about 598 unreturned. Actual figures may change as the incident progresses; please refer to the latest sources.

What user data did Revolut leak? ▼

According to a Decrypt report on September 12, 2026, Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests. This is highly sensitive personal data that may be used for targeted phishing and identity impersonation.

Do OKX users need to worry about a breach similar to Revolut's? ▼

OKX users do not need to directly worry about the Revolut incident itself, but should be vigilant against similar social engineering and official impersonation attacks. It is recommended to immediately check account login devices, API keys, and withdrawal addresses, and enable two-factor authentication and withdrawal whitelists.

How to enable OKX two-factor authentication and withdrawal whitelist? ▼

You can go to the OKX official App or website security center to enable a time-based one-time password (TOTP) or hardware key, and set a withdrawal whitelist to restrict assets to pre-confirmed addresses. Specific paths are subject to OKX's latest official documentation.

What to do if you receive an email or call claiming to be OKX customer service? ▼

Do not click links, disclose passwords, 2FA codes, or API keys. Re-confirm through the built-in customer service channel in the OKX official App or website, and beware of customer service numbers from search engine ads or unfamiliar emails.

Related Insights

View all →
tutorial

September 7, 2026 Crypto Market Wrap: Bitcoin and Ethereum Prices, Capital B Adds 376 BTC, and Liquid Hacker Returns $270 Million

September 7, 2026 market snapshot: BTC/ETH opening prices and dips, Capital B's 376 BTC buy, Liquid hacker's $270M return, and safe Bitcoin buying guide.

tutorial

Bitcoin rebounds 38% from July low: 600 dormant 16-year BTC transfer, BlackRock ETF asset growth, and Robinhood Chain mainnet launch explained

Bitcoin rebounds 38% from July low; 600 dormant BTC moved; BlackRock ETF assets at $60.2B; Robinhood Chain launched; OKX verifiable market and risk notes.

tutorial

Bitcoin ETF posts $217M single-day net inflow, BlackRock contributes 95%; Ethereum, XRP and other altcoin ETFs see consecutive net inflows in 2026

On Sep 1, 2026, US spot Bitcoin ETFs had a $217M net inflow with BlackRock at 95%; ETH ETFs extended to 11 days and XRP/Solana ETFs to 10 days of net inflows.

tutorial

Why Is Bitcoin Going Up? BTC Breaks $80,000 on August 24, 2026 as Short Liquidations Top $220 Million and Strive Adds 1,110 BTC

Bitcoin broke $80k on Aug 24, 2026 amid $220M+ short liquidations and Strive's 1,110 BTC buy, per Cointelegraph. OKX for verification; not investment advice.

tutorial

Fed September Rate Hike Probability Rose to 66.1%: Bitcoin and Ethereum Both Fall; PCE and Oil Price Risk Analysis

Sep 8, 2026 Bitcoin $79,093.85 (-1.6%), Ethereum $2,489.84 (-1%); Fed Sep hike odds 60% vs 66.1% Aug 31; July PCE 3.7% headline, 3.3% core, oil near $100.

tutorial

CLARITY Act Senate Cloture Vote Fails 49-50: Strategy Holds 845,050 BTC, Strive Rises to 25,000 BTC

On September 15, 2026, the CLARITY Act cloture vote failed 49-50; Strategy held 845,050 BTC and Strive rose to 25,000 BTC. A risk guide for OKX users.