Liquid Attackers Return 3,400 Bitcoin (BTC) to Federation Wallet

Hackers returned 3,400 BTC — 85% of the Liquid Network haul — after Blockstream patched bridge nodes. About 598.5 BTC worth $47M remains with the attackers.

(10:30 PM UTC)
4 min read
AI SummaryAI
  • Attackers returned 3,400 BTC to the Liquid Network federation wallet on September 7, about 85% of the haul.
  • About 598.5 BTC worth roughly $47 million remains at the attackers' address.
  • The refund confirmed in Bitcoin block 965,950 at 19:09 UTC on September 7.
  • Liquid peg-outs normally require approval from 11 of 15 federation companies.
j5wc1pnr

3,400 BTC Back in the Liquid Peg

The group behind last weekend's breach of the Liquid Network, Blockstream's Bitcoin sidechain, has given back the bulk of what it took. On Monday, September 7, the self-described white hats returned 3,400 BTC to the federation wallet — roughly 85% of the nearly 3,998 BTC they consolidated and pulled from the network over the weekend in a transfer worth about $320 million at the time. Liquid lets users lock Bitcoin on the mainnet and receive L-BTC, a faster and more private wrapped Bitcoin token, and the sidechain also anchors a meaningful share of early Bitcoin DeFi activity. What makes the incident unusual is the path the funds took: a peg-out ordinarily requires sign-off from 11 of the 15 companies that operate the federation, yet the weekend withdrawal went to a freshly created address instead. The peg authorization keys themselves were not compromised, and other issued assets on the chain were unaffected — but the network was paused and L-BTC movements frozen as a precaution, as we covered when Liquid halted following the drain.

Talks Conducted in OP_RETURN

The refund followed a negotiation conducted entirely inside Bitcoin blocks. The holders first published an OP_RETURN message — arbitrary data attached to a transaction — reading “contact us on chain”, sent from the address controlling the taken pile; a Blockstream-linked address answered by directing them to an email contact. Later notes from that sender carried Electrum-encrypted payloads and PGP signatures that anyone can verify against Blockstream's published security key. In block 965,869, the attackers asked in plain text whether returning “most” of the funds to the federation script would be acceptable, then set their condition: patch the bug first, make sure every node running the bridge is updated, and only then move the money. Blockstream replied “Yes, thank you” in a clear-signed message and later broadcast: “Bridge nodes are patched, safe to return the funds.” Minutes after that confirmation, the 3,400 BTC return transaction was confirmed on Bitcoin's proof-of-work ledger in block 965,950 at 19:09 UTC. The split was lopsided but deliberate — 85% sent back, 15% retained as an implied finder's fee — and it came only after the technical demand had been demonstrably met.

598.5 BTC Still Held by Attackers

What remains is the sticking point: 598.5 BTC, worth approximately $47 million at Monday's price near $79,100, still sits at the attackers' address, and neither side has explained why. That level is one Bitcoin has defended recently, holding near $79,000 even as macro pressures built. The silence around the retained sum has drawn scrutiny from security figures. Charles Guillemet, chief technology officer at hardware wallet maker Ledger, wrote on X that if the retained coins represent a negotiated reward under an encrypted on-chain contract, the arrangement “looks more like extortion than white-hat hacking.” The aftermath lends weight to his caution: multiple encrypted messages were posted on-chain after the refund, ending with a sad-face emoji from the attackers' side — a signal that attempts to shrink the bounty went nowhere. Blockstream has made no public statement on the negotiation itself. The company shut the bridge on Sunday and asked exchanges to freeze L-BTC deposits and withdrawals, and it has not said when service resumes. On-chain data attributes the original leak to an Elements bug in the SideSwap peg-out path, leaving the holder address among the larger tracked whale balances in the ecosystem.

The $47M Question Before Reopening

For COINOTAG, the episode is notable because every load-bearing claim can be checked against primary artifacts rather than statements alone: the refund is settled on-chain, the retained balance is visible at the holder address, and the remediation — patched bridge nodes — was confirmed by Blockstream's own signed message before any coins moved. Root cause was traced to an Elements bug in the peg-out path, with the federation's authorization keys intact. What now determines the outcome is the unreturned 15% and the timeline for reopening the bridge. Until Blockstream lifts the L-BTC freeze, the sidechain's wrapped supply stays locked, and the fate of roughly $47 million in attacker-controlled coins remains the open variable in an otherwise documented recovery.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.