Blockstream Refuses to Pay Ransom, Liquid Hacker Still Holds Nearly 600 BTC; Revolut User Data Breach Explained
Blockstream refused to pay a ransom while the Liquid hacker held about 598 BTC, and Revolut leaked user passports and transaction data; learn OKX safety steps.
Article Citation Summary
Blockstream refused to pay a ransom while the Liquid hacker held about 598 BTC, and Revolut leaked user passports and transaction data; learn OKX safety steps.
Core Summary: As of public reports on September 12, 2026, Blockstream refused to pay a 10% bounty to the Liquid network hacker, who still holds about 598 BTC; Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests. For OKX users, the focus is not just watching the events but immediately checking account security settings, enabling two-factor authentication, setting up withdrawal whitelists, and staying vigilant against phishing requests impersonating officials.
Incident Review: Blockstream Refuses to Pay Ransom and the Liquid Hacker's 598 BTC

What did the hacker demand?
According to a Cointelegraph report on September 11, 2026, the hacker withdrew approximately 4,000 bitcoins (worth about $320 million at the time) from the Liquid alliance wallet, then returned 3,400, leaving about 598 unreturned. The hacker demanded that Blockstream pay a 10% bounty from its own funds, otherwise Liquid holders would face a 15% loss.
Why did Blockstream refuse?
Blockstream refused to pay the ransom and condemned the hacker's actions as theft rather than white-hat activity. This stance indicates the platform is unwilling to provide positive incentives for attacks, but Liquid users still need to monitor subsequent asset return progress. The facts in this section come solely from the Cointelegraph report and may continue to update.
Revolut User Data Breach: How Passports and Bitcoin Transaction History Were Tricked Out by Fake Government Requests
What was the scope and type of leak?
According to a Decrypt report on September 12, 2026, Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests. The leaked information at least includes passport data and Bitcoin transaction history, which is highly sensitive personal data.
What risks do users face?
Such data breaches may lead to targeted phishing, identity impersonation, and asset-targeting attacks. Attackers can combine passport information with transaction history to craft more deceptive official notices or customer service contacts. Although OKX users are not involved in this incident, they should be wary of similar social engineering tactics.
What It Means for OKX Users: Mapping and Self-Check of Similar Risks
Comparison of Key Facts in the Two Incidents
| Incident | Key Facts | Main Risks | Implications for OKX Users |
|---|---|---|---|
| Blockstream refuses to pay ransom | Hacker withdrew about 4,000 BTC, returned 3,400, still holds about 598; Blockstream refused to pay 10% bounty | Liquid holders may face asset loss; platform does not reward attacks | Monitor custodian security, avoid transfers induced by social engineering |
| Revolut user data breach | Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests | Targeted phishing, identity impersonation, asset-targeting attacks | Protect personal identity information and transaction privacy, beware of fake customer service |
What similar risks might my OKX account face?
The common points of the two incidents are social engineering, impersonating officials, and custodian attacks. Although OKX users are not involved in these incidents, they cannot relax their vigilance. Attackers may use similar leaked data to impersonate OKX customer service or regulatory agencies, tricking users into giving up passwords, 2FA codes, or API keys.
How to determine if you are affected?
Users should check login devices, API keys, withdrawal address lists, and recent activity records on their OKX account. Any urgent notification claiming to be from OKX or request for passwords or verification codes should be re-confirmed through official channels. Specific verification paths should refer to the latest instructions in the OKX official App or website help center.
Actionable Protection Steps: An OKX Security Checklist Distilled from the Two Incidents
How to enable two-factor authentication?
- Log in to the OKX official App or website and go to the account security or security center page.
- Find the two-factor authentication (2FA) option and choose a time-based one-time password (TOTP) or hardware key.
- Follow the prompts to bind the authenticator and save the recovery code to complete activation.
How to set up a withdrawal whitelist?
- Find the withdrawal whitelist function in security or withdrawal settings.
- Add pre-confirmed withdrawal addresses and enable whitelist restrictions so assets can only be transferred to confirmed addresses.
How to identify fake requests?
- Do not click unknown links, and do not disclose passwords, 2FA codes, or API keys to anyone.
- Contact the platform through the built-in customer service channel in the OKX official App or website, and do not trust customer service numbers from search engine ads or unfamiliar emails.
- Regularly check account activity, device lists, and API permissions, and promptly remove authorizations that are no longer used.
OKX Security Self-Check Checklist
| Category | Specific Action | Purpose |
|---|---|---|
| Two-factor authentication | Log in to OKX official App or website, go to security center, enable TOTP or hardware key | Prevent unauthorized account login |
| Withdrawal whitelist | Add pre-confirmed addresses in withdrawal settings, enable whitelist restrictions | Assets can only be transferred to confirmed addresses |
| Fake request identification | Do not click unknown links, do not disclose password/2FA/API keys, confirm through official built-in customer service | Prevent phishing and social engineering |
| Regular self-check | Check login devices, API keys, withdrawal addresses, activity records, remove unused authorizations | Detect anomalies and stop losses in time |
The above steps are based on general security practices and outline requirements. Specific feature names and operation paths should refer to OKX's latest official documentation.
FAQ and Risk Disclaimer
What is the latest progress on these incidents?
As of September 12, 2026, public reports show the Liquid hacker still holds about 598 BTC, and the Revolut breach has been exposed. For subsequent progress, please check primary sources such as Cointelegraph and Decrypt; this article does not replace real-time verification.
How does OKX Radar verify information?
As an independent third-party media, OKX Radar only provides incident interpretation and security education based on public sources, and does not provide trading or legal advice. All security operation suggestions in this article should be based on OKX's latest official documentation, and users should assess applicability on their own.
Risk Disclaimer: Crypto/digital asset prices are highly volatile, and materials and rules may change at any time. This article does not constitute investment, legal, or tax advice. Before making decisions, refer to the latest official announcements and actual product pages.
References and verification links
These are the article-level sources stored with this page. Interpret dynamic facts and rules in light of their dates, regions, and subsequent updates.
FAQ
Why did Blockstream refuse to pay the ransom? ▼
Blockstream refused to pay a 10% bounty to the Liquid network hacker and condemned the hacker's actions as theft rather than white-hat activity. This stance comes from a Cointelegraph report on September 11, 2026, and may be updated later.
How much BTC does the Liquid hacker still hold now? ▼
As of the Cointelegraph report on September 11, 2026, the Liquid hacker withdrew about 4,000 BTC and returned 3,400, still holding about 598 unreturned. Actual figures may change as the incident progresses; please refer to the latest sources.
What user data did Revolut leak? ▼
According to a Decrypt report on September 12, 2026, Revolut leaked users' passports and Bitcoin transaction history to fraudulent government requests. This is highly sensitive personal data that may be used for targeted phishing and identity impersonation.
Do OKX users need to worry about a breach similar to Revolut's? ▼
OKX users do not need to directly worry about the Revolut incident itself, but should be vigilant against similar social engineering and official impersonation attacks. It is recommended to immediately check account login devices, API keys, and withdrawal addresses, and enable two-factor authentication and withdrawal whitelists.
How to enable OKX two-factor authentication and withdrawal whitelist? ▼
You can go to the OKX official App or website security center to enable a time-based one-time password (TOTP) or hardware key, and set a withdrawal whitelist to restrict assets to pre-confirmed addresses. Specific paths are subject to OKX's latest official documentation.
What to do if you receive an email or call claiming to be OKX customer service? ▼
Do not click links, disclose passwords, 2FA codes, or API keys. Re-confirm through the built-in customer service channel in the OKX official App or website, and beware of customer service numbers from search engine ads or unfamiliar emails.