Wild? No, this is exactly how you should deal with retards.
-snip
No ransoms should ever be paid, this is the core of cybersecurity. Fuck them and their bullshit. They deserve everything that is coming to them.

I agree with you, we are on the same mind regarding ransom. Since they're using the BTC as leverage in the negotiation.
But also, don't really like the action of Blockstream after getting 3,400 BTC back. They're the ones who make these hapens can be happen in the first place through their shitty security they have. They don't even have a clear bounty policy at all. Even a project with a clear bounty and having so much volunteer work for the security check can still get situations like these.
We can agree the companies can and do have terrible policies or a lack thereof, but what about that? Is every company supposed to have that simply because that is the optimal configuration? Of course not, we are not demanding optimal behavior from practically any company with anything. Furthermore, should someone who discovers a security exploit be allowed to demand anything from that company? Whether for them to change their policies or a ransom? That is neither the case. They should improve their policies, but that is not directly relevant to the unresolved case here.
I don't see any words, at least "THANK YOU" for the 3,400 BTC back on the statement. At least the first word in the statement should be "THANK YOU" for 3,400 BTC, even though we don't like it at all, with the movement of those hackers who claim to be white-hats. A courtesy first would be very wise, and then they can continue making statements like that.
It depends a lot on what kind of personality you have and what kind of approach you usually take with these things. I would also not provide a "THANK YOU" to someone who is trying to ransom money from me knowing that
the only reason for which they returned the other part of it was because they believe that they can get away with this legally. In the end, who decides what the payout is supposed to be for an exploit if you are a "white hat hacker"? The company in question.
Therefore, even in the case of a catastrophic bug such as this one the company can decide that it is worth $500 to them and pay this out. Would that make it a shitty company? It would, but that does not change the fact that the authority to decide the payout
solely rests with them. A real white hat would take the money (or outright refuse it if it is insulting) and complain, but he would move on. Bad people would try to do all sorts of things, such as the ransom attempt here. So
FUCK THEM, they don't deserve a "THANK YOU". That's more my style, that's why it resonates with me.