📈 Get daily crypto insights that make you smarter about your money

Liquid Network Attacker Promises to Return Most of the 4,000 BTC — but Only After Blockstream Patches the Bug

The hacker who drained roughly 4,000 BTC from the Liquid Network’s federation wallet says they will return most of the funds — but only after Blockstream proves the underlying software bug is fully patched.

The standoff, which began over the weekend when the Bitcoin sidechain disclosed that about 4,000 BTC (worth roughly 320 million USD at the time) had been withdrawn from its federation wallet, has now shifted into an unusual onchain negotiation between the Adam Back-led Blockstream and the party claiming to be a white-hat researcher.

## An onchain conversation written in bitcoin

The communication itself is a rare piece of blockchain theater. The purported white hat has been talking to Blockstream through Bitcoin OP_RETURN messages and PGP-encrypted text — embedding notes directly into bitcoin transactions rather than using email or social media.

In a message attached at block 965,875, the attacker told Blockstream to “fix the bug first” and to make sure every node in the federation is patched before any funds are transferred back. The message followed an earlier communication in which the party offered to send most of the bitcoin back to the federation address.

Blockstream responded in kind, sending a PGP-signed onchain message stating: “Bridge nodes are patched, safe to return the funds.” The signature checks out against the security key published on Blockstream’s official website, according to The Block. At the time of publication, the roughly 4,000 BTC still sat in the attacker’s wallet.

Blockstream had opened the channel earlier, contacting the party through a transaction at block 965,822 and asking them to get in touch with the company’s security team.

## How the withdrawal actually happened

New details from SideSwap, the trading platform caught in the middle of the incident, help explain how 4,000 BTC left the federation wallet without a single private key being stolen.

According to a statement from SideSwap on X, the affected transaction involved 4,000 L-BTC — Liquid’s wrapped bitcoin — sent to its peg-out service. The service burned the tokens using a valid peg-out authorization, after which the Liquid Federation paid out 3,996 BTC to the customer’s Bitcoin address. In other words, the system worked exactly as designed; the problem was that the tokens it processed should never have existed.

Blockstream later established that the L-BTC had been created through a bug in Elements, the open-source software that powers Liquid, SideSwap said. The platform emphasized that neither its own systems nor its peg-out authorization key were compromised. The SideSwap Peg-out Authorization Key itself was not breached, the network confirmed.

The sequence matters for anyone holding L-BTC: this was not a key compromise or a hack of an exchange’s hot wallet. It was a minting flaw in the sidechain’s core software that allowed counterfeit wrapped bitcoin to be created and then legitimately redeemed for the real thing.

## Network still frozen

Liquid remains paused while the situation unfolds. Bridge nodes are disabled, LBTC deposits and withdrawals remain suspended at exchanges, and SideSwap said swaps, peg-ins, and peg-outs will stay frozen until the network resumes.

The pause is the federation’s way of making sure no additional tainted L-BTC can be created or redeemed while every node operator patches the Elements bug. It is an uncomfortable but familiar pattern in bitcoin sidechain history: federation members would rather halt everything than risk a second, larger withdrawal.

For users, the freeze is a reminder of the trade-off at the heart of wrapped assets. L-BTC only holds its value while the federation, the peg-out process, and the underlying software all behave as intended. A bug in any of the three can leave holders unable to move funds — even when, as in this case, the underlying bitcoin reserves appear to remain intact.

## What comes next

The ball is now in the attacker’s court. Blockstream’s signed message says the bridge nodes are patched, which was the stated condition for returning the funds. If the party follows through on its promise to send back “most” of the 4,000 BTC, the incident could end as one of the largest negotiated recoveries in crypto history — a 320 million USD outcome resolved not by courts or law enforcement, but by PGP signatures and OP_RETURN messages.

The word “most” is doing real work in that sentence. It is not yet clear whether the attacker intends to keep a bounty for themselves, or whether the remaining funds cover fees or some other cost. Until the coins actually move back to the federation address, the recovery remains a promise written into the blockchain rather than a settled fact.

The episode also puts fresh scrutiny on Elements and on sidechain security more broadly. The software has powered Liquid since its launch, and the bug that allowed unauthorized L-BTC creation will inevitably raise questions about audits, testing, and how quickly federation members can coordinate around a critical patch.

For now, the market appears to be treating the incident as contained. Bitcoin itself has been little changed since the weekend, and the focus has stayed on the onchain negotiation rather than any broader contagion.

Price snapshot at publication: BTC traded around 79,000 USD, ETH near 2,479 USD, and SOL around 104 USD (14:45 UTC, Sept. 7, 2026).

12 thoughts on “Liquid Network Attacker Promises to Return Most of the 4,000 BTC — but Only After Blockstream Patches the Bug”

  1. Negotiating via OP_RETURN at block 965875 with PGP notes attached is the most cyberpunk press release ever. 4000 BTC riding on whether Blockstream ships a patch first.

    1. opreturn_olof the leverage play is obvious. Fix the bug or the funds sit in limbo. Whoever this is understands incentive design better than most auditors.

  2. negotiating a 320 million dollar return via OP_RETURN memos is the most bitcoin thing ive ever seen. no lawyers, just block 965875

    1. white hat or not, holding 4000 btc until a patch ships is serious leverage. hope they audited more than just the bridge nodes

  3. The PGP signature checking out against the key on Blockstream’s official site is a good sign. At least both sides are proving identity properly.

    1. pgp over op_return is cool until you remember anyone can trace the whole standoff on a block explorer. very public negotiation

      1. tracing it is the point though. a negotiation fully onchain is exactly what makes a quiet fake return harder to pull off

  4. federationfraud_

    Everyone calling this a white hat should pump the brakes until coins actually move. Promising to return most of 320 million USD costs nothing to promise.

    1. ‘most of 320 million’ is doing a lot of work in that promise. even 90 percent back leaves this person 30m plus for finding one bug

      1. even 90 percent back makes this the smoothest bug bounty in history. blockstream should just hire whoever it is before someone less polite finds the next federation bug

    2. federationfraud_ fair point, but demanding every federation node be patched before transfer is at least a coherent condition. Time will tell if L-BTC holds.

  5. the fix the bug first demand is honestly fair. returning funds into the same vulnerable federation wallet would just invite round two

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$78,971.00-0.9%ETH$2,479.81-0.1%SOL$103.75-2.2%BNB$739.54-1.0%XRP$1.39-1.3%ADA$0.2208+0.9%DOGE$0.0901+0.9%DOT$1.10+13.5%AVAX$8.06+5.4%LINK$12.93+4.8%UNI$6.86-5.8%ATOM$1.66+4.4%LTC$55.75+2.0%ARB$0.1641-12.7%NEAR$2.32-5.2%FIL$0.8727+9.9%SUI$0.8130+1.3%BTC$78,971.00-0.9%ETH$2,479.81-0.1%SOL$103.75-2.2%BNB$739.54-1.0%XRP$1.39-1.3%ADA$0.2208+0.9%DOGE$0.0901+0.9%DOT$1.10+13.5%AVAX$8.06+5.4%LINK$12.93+4.8%UNI$6.86-5.8%ATOM$1.66+4.4%LTC$55.75+2.0%ARB$0.1641-12.7%NEAR$2.32-5.2%FIL$0.8727+9.9%SUI$0.8130+1.3%
Scroll to Top