Skip to content
  • BTC$75,403−3.13%
  • ETH$2,390−4.86%
  • SOL$96.38−5.55%
  • XRP$1.27−10.54%
  • BNB$708.84−1.80%
  • DOGE$0.0795−5.18%
  • ADA$0.1925−7.38%
  • LINK$10.78−6.91%
Technology

Liquid Recovers 3,400 BTC as Hackers Return Funds

Purported white-hat hackers returned 3,400 of the 4,000 BTC drained from Blockstream's Liquid Network, keeping 598.5 BTC while the sidechain stays paused.

Rare Dollar Newsroom 3 min read
Lines of code on a dark screen with a padlock, illustrating the Liquid Network security incident
Pexels

In this story

  • BTC $75,403 −3.13%

Blockstream’s Liquid Network has recovered the bulk of the bitcoin that left its federation wallet on Sunday. The parties behind the roughly 4,000 BTC withdrawal — about $320 million at the time, close to 95% of the sidechain’s reported reserves — sent 3,400 BTC, worth roughly $268 million at current prices, back to the federation address after Blockstream said its bridge nodes were patched. They kept 598.5 BTC, about $47 million, with no published explanation for the retained balance, and Liquid remains paused.

What came back, and what did not

On September 7 at 09:19:46 UTC, Blockstream posted a PGP-signed message confirming its bridge nodes had been updated and that it was “safe to return the funds,” according to Blockstream’s status page and reporting by Bitcoin.com News. The actors broadcast a transaction sending 3,400 BTC back to the federation address shortly after; on September 8, Blockstream said it and the Liquid Federation had been “working diligently to resolve the ongoing situation and ensure the return of assets.”

The remainder — 598.49955894 BTC — is still sitting at the actors’ address. Nothing in the on-chain messages identifies the roughly 15% share as an agreed bounty, and no agreement explaining it has been published.

A bug, not a stolen key

Neither Blockstream nor Liquid has said federation keys were compromised. The funds left through SideSwap’s Peg-out Authorization Key, the mechanism SideSwap uses to authorize withdrawals, but the failure happened earlier in the chain. Independent technical reconstructions point to a range-proof verification cache bug in Elements, the Bitcoin Core fork that Liquid nodes run, which let the actors create L-BTC that was not backed by deposited bitcoin; those tokens were then exchanged for real bitcoin through SideSwap’s peg-out service.

The timeline fits a long-unpatched flaw: reporting by Protos noted that Liquid’s functionary codebase, which federation members run to process peg-ins and peg-outs, had not been updated in more than two years before the exploit. A commit posted to the Elements repository on September 1, five days before the incident, addressed a case where “a dynafed header with a mismatched height could be accepted,” though Blockstream has not confirmed that commit was the vulnerability exploited.

The network stays frozen

Recovering 3,400 BTC takes pressure off the reserve, but it has not restarted the network. Bridge nodes remain disabled, no new transactions can be submitted, and LBTC deposits and withdrawals stay halted at exchanges. Other assets issued on Liquid — USDT, DePix and tokenized real-world assets — were not touched, and Bitcoin’s mainchain was unaffected; Liquid wallets such as Aqua are only disrupted in their Liquid functionality.

Reporting from Bitcoin.com News says a restart depends on operators proving legitimate L-BTC is again backed 1:1, distributing a patched Elements release across the network, and deciding the bridge can safely reopen. None of those steps had been completed as of Monday evening.

What this does NOT tell you

First, the “white-hat” label is still contested. Liquid itself has called the actors “purported white-hat hackers”; Ledger CTO Charles Guillemet questioned the take-first-and-negotiate-later approach, though he later allowed that they could be inexperienced researchers, according to Bitcoin.com News. Returning most of the funds after a patch is consistent with a genuine disclosure, but the 598.5 BTC retention has no published justification.

Second, this is not a story about Bitcoin or about self-custody. Bitcoin’s consensus was not involved; the failure sits in the application and federation layer that backs LBTC, which is a different threat model from holding mainchain bitcoin directly. Third, the verifiable parts of this story are all on-chain — the return transaction and the retained address are public records. The unverifiable parts — motives, and whatever agreement produced the return — are not.

Most of the money is back, and the vulnerability that let it leave has, by Blockstream’s account, been patched. The harder question the pause now tests is trust: whether a federated sidechain whose validation code went unpatched for years can reopen with LBTC holders’ confidence intact — and what happens to the 598.5 BTC that did not come home.

Sources

  1. Blockstream status: Liquid security incident
  2. Blockstream on X (September 8, 2026)
  3. Bitcoin.com News: Liquid hackers return 3,400 BTC, keep $47M as network stays frozen
  4. The Block: Liquid Network attacker says they will return most of 4,000 BTC after bug fix
  5. Return transaction on mempool.space
Entities Bitcoin