Liquid Network Attackers Return 3,400 Bitcoin (BTC) After Weekend Peg-Out Incident
Liquid Network attackers returned 3,400 BTC, 85% of the roughly $320M drained from the federation wallet, while 598.5 BTC worth ~$47M remains unreturned.
AI SummaryAI
- Liquid Network attackers returned 3,400 BTC to the federation wallet on September 7, roughly 85% of the stolen funds.
- 598.5 BTC, worth about $47 million, remains held at the withdrawal address.
- A SideSwap client transferred 4,000 L-BTC at 14:05 UTC Sunday, releasing about 3,996 BTC from federation custody.
- Blockstream attributed the incident to an Elements software flaw that allowed invalid L-BTC generation.
3,400 BTC Back in Federation Wallet
The group that drained approximately 4,000 Bitcoin (BTC) — around $320 million — from the Liquid Network sidechain's federation wallet over the weekend has returned 3,400 BTC, or roughly 85% of the extracted funds. On-chain data confirms the settlement transaction reached the federation at 16:09:25 UTC on Monday, September 7, restoring assets valued at approximately $269.2 million at the time of the return. Roughly 598.5 BTC, worth about $47 million, remains sitting at the address used for the withdrawal — a whale-sized stake the group has yet to explain. The incident began on September 6, when a user pushed 4,000 L-BTC, the sidechain's 1:1 Bitcoin-pegged asset, through SideSwap's peg-out service, drawing real BTC out of federation custody. The group then claimed, via messages embedded in Bitcoin transactions, to be white-hat hackers exposing a security flaw rather than thieves. They pressed Liquid developer Blockstream to patch the bug first, warning that the chain remained dangerous even on the latest code and promising to return the funds safely once all nodes were patched. Blockstream subsequently broadcast a signed message stating the bridge node had been patched and the funds could be returned safely — after which the group sent back the 3,400 BTC. Liquid had already disabled its bridge nodes and asked exchanges to halt L-BTC deposits and withdrawals while the incident unfolded. Not everyone accepts the white-hat framing. Charles Guillemet, chief technology officer at Ledger, noted that with 600 BTC still withheld and no pre-agreed bounty in place, the operation “looks closer to extortion than white-hat hacking.” Liquid has not disclosed how it will handle the remaining funds or any potential shortfall in L-BTC reserves, and the sidechain's peg services remain suspended as of publication.
A Valid Peg-Out With No Backing
The recovery, however significant, does not resolve the most troubling part of the incident: the withdrawal went through the expected authorization path without any key compromise. Liquid's official account reported that SideSwap's authorization key was not misused. Per the platform's own timeline, a client transferred 4,000 L-BTC to SideSwap's peg-out service at 14:05 UTC on Sunday, and after a valid peg-out authorization was presented, the federation wallet released approximately 3,996 BTC at 14:28:56 UTC. The problem sat upstream. Blockstream later determined the root cause was a flaw in the Elements software, the codebase underlying Liquid, which allowed the creation of invalid L-BTC. That meant the peg mechanism processed tokens that looked legitimate but were never backed by the custodial Bitcoin the two-way peg is supposed to guarantee. Under Liquid's Bitcoin DeFi architecture, L-BTC functions like a wrapped Bitcoin equivalent, with each token redeemable for BTC held by the federation of functionaries. If an invalid token can enter through the redemption path, reserve integrity matters every bit as much as key security, and the incident moves from classic key-theft territory into accounting risk. The distinction is what makes this a stress test for sidechain design in the broader Bitcoin ecosystem rather than an isolated breach: core Bitcoin was never at risk, yet a software bug allowed a redemption request that appeared valid to clear against reserves that did not actually exist behind it. That accounting gap — real BTC leaving custody against L-BTC that should never have counted as valid collateral — is the structural weakness now under scrutiny, regardless of whether the remaining coins come home.
Reserve Gap Still Open
Taken together, the two threads of this story point to one conclusion: the recovery was the easy part. The on-chain settlement record and Blockstream's signed post-mortem confirm the federation is made whole to within 598.5 BTC, but the root cause — an Elements flaw that let unbacked L-BTC pass a legitimate-looking authorization check — has implications for every pegged asset in the Bitcoin ecosystem. Our read: until Liquid publishes the vulnerability's full cause, its remediation plan, and how the remaining reserve shortfall will be covered, the sidechain's peg remains a live question. Our coverage of the federation-wallet recovery tracks the full timeline in detail.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


