← BACK TO FEED
Liquid NetworkBitcoinBlockstreamwhite hatsidechain security

Liquid Hackers Give Back Most of the Bitcoin, Keep $47M as Apparent 'Fee'

Hackers exploited a bug in the Elements software underlying the Liquid Network sidechain to withdraw nearly 4,000 bitcoin (~$320M) from its federation wallet on September 6. The following day, the group — claiming to be white hats — returned 3,400 bitcoin (~$265M) after Blockstream confirmed its nodes had been patched, but approximately 598.5 bitcoin (~$47M) remains unreturned. While Blockstream says it is still in contact with the group and is preparing to restart the network, critics such as Ledger's CTO have questioned the white-hat label, suggesting the retained funds may amount to extortion.

The group that drained nearly 4,000 bitcoin from the Liquid Network last Sunday returned 3,400 of it the following day. On-chain records confirm the transfer hit a Liquid Federation address at 16:09 UTC on September 7. That's roughly 85% of what walked out the door.

The remaining 598.5 bitcoin? Still sitting at the source address as of September 8. That chunk isn't a separate transaction — it's change from the same payment, sent back to where the funds originated. At bitcoin's price around $78,000 that day, the returned slice was worth about $265 million. The bit still missing: roughly $47 million.

Neither Blockstream nor the Liquid Network has publicly confirmed whether that $47 million is part of any negotiated arrangement.

For anyone who missed the original incident: Liquid is a Bitcoin sidechain. It holds real bitcoin in reserve to back a token called L-BTC. Blockstream, which provides the underlying technology, said self-described white hat hackers exploited a bug in Elements — the software Liquid runs on — to generate L-BTC without legitimate backing, then used SideSwap's Peg-out Authorization Key to convert it into real bitcoin. The withdrawal stripped out roughly 95% of Liquid's reported reserves, which had stood at around 4,200 bitcoin beforehand.

SideSwap confirmed neither its systems nor its key were directly compromised. Blockstream echoed that. The vulnerability was in the Elements software itself, though neither party has publicly described exactly what the flaw was.

What followed was, frankly, bizarre. The two sides negotiated on-chain, writing messages into Bitcoin transactions. The attackers opened with 'we are whitehats. contact us on chain.' They then demanded the bug be patched and every node updated before they'd return anything. Blockstream replied with a signed message confirming its bridge nodes had been patched. A transaction at 15:31 UTC on September 7 carried a PGP-encrypted message to the federation address along with 1,000 satoshis. The contents remain private. The 3,400 bitcoin followed 38 minutes later.

Blockstream says updated software has been deployed and that federation members are working toward a coordinated network restart. Samson Mow, CEO of JAN3 and a former Blockstream executive, confirmed the roughly 598 bitcoin figure and said Blockstream remains in contact with the group. The Liquid Network remains paused, meaning L-BTC holders still cannot redeem their tokens for bitcoin.

Mow has urged users not to send bitcoin to Liquid's peg-in addresses until the restart is officially confirmed. Other assets on Liquid — USDT and DePix among them — are reportedly unaffected.

Not everyone is buying the white-hat framing. Ledger CTO Charles Guillemet was blunt about it: if those 600 bitcoin were negotiated as a reward through encrypted blockchain messages, that looks a lot more like extortion than responsible disclosure. Hard to argue with that read.

WATCH THE SHORT
READ NEXT
Liquid Network Hackers Return Most of the $320M Bitcoin They Nicked, Hold Rest as LeverageSomeone Just Walked Off With 95% of Liquid Network's Bitcoin and Wants a Pat on the BackCritical Alby Hub Flaw Left Internet-Exposed Bitcoin Wallets Open to Takeover