Liquid 'White Hats' Return 3,400 Bitcoin (BTC) to Federation Wallet
White hats returned 3,400 BTC to Liquid's federation wallet, 85% of drained funds; 598 BTC worth $47M remains outstanding and the network is still paused.
AI SummaryAI
- White-hat actors returned 3,400 BTC to Liquid's federation wallet at Bitcoin block height 965,950.
- About 598 BTC, worth roughly $47 million, remains under the actors' control.
- The breach drained roughly 4,000 BTC from Liquid's ~4,200 BTC reserve, leaving 197 BTC.
- Blockstream traced the root cause to a bug in the Elements software underpinning Liquid.
3,400 BTC Back in the Federation Wallet
Purported white-hat hackers returned 3,400 Bitcoin (BTC) to the Liquid Network's federation wallet on Monday, handing back roughly 85% of the approximately 4,000 BTC drained from the reserves backing the sidechain's L-BTC token. On-chain records show the repayment landed in a single transfer at Bitcoin block height 965,950, worth about $270 million at prevailing prices, against an initial outflow valued near $320 million. Liquid, built by Blockstream as a faster and more private settlement layer atop Bitcoin, is meant to hold real BTC in a shared federation wallet so every L-BTC stays backed one-for-one, much like wrapped Bitcoin structures. Sunday's unauthorized peg-out emptied nearly the entire reserve of around 4,200 BTC down to just 197 BTC, briefly breaking that backing. Operators disabled bridge nodes, paused the network and told exchanges to freeze L-BTC deposits and withdrawals; other Liquid-issued assets, including tether, were unaffected. The swift return has narrowed the collateral gap, but about 598 BTC — roughly $47 million — remains in addresses the actors control, and the network is still offline. The incident doubles as a stress test for Bitcoin sidechain security overall.
On-Chain Negotiations Over the Remaining 598 BTC
What turned a potential $320 million loss into a partial recovery was an unusual negotiation conducted entirely on the Bitcoin blockchain. The actors labeled themselves “whitehats” in OP_RETURN messages and said they would hand back the funds only after the flaw was fixed and every node had installed the patch. Blockstream responded with PGP-signed on-chain messages stating the bridge nodes were patched and it was safe to return the money; the 3,400 BTC repayment followed. From a consolidated balance of about 3,998.5 BTC, the return worked out to roughly 85%. Samson Mow said Monday that approximately 598 BTC remains outstanding and that Blockstream continues to engage with the group, with the network staying paused while further security improvements are made. Not everyone accepts the white-hat framing: Ledger chief technology officer Charles Guillemet argued that retaining nearly 600 BTC without a pre-agreed bounty looks, in his words, “more like extortion than white-hat hacking.” Neither Blockstream nor Liquid has publicly described the retained funds as a negotiated bug bounty, and no repayment terms have been disclosed — the single largest open question in this case.
Elements Bug, Not a Stolen Key
Disclosures from Liquid and SideSwap rule out the earliest theory — that SideSwap's keys had been stolen. The withdrawal used SideSwap's legitimate Peg-out Authorization Key (PAK), the credential that authorizes the federation to release BTC during redemptions, and neither that key nor the federation's other signing keys were compromised. Blockstream instead traced the root cause to a bug in Elements, the open-source software underpinning Liquid, which allowed L-BTC without matching BTC reserves to be created. To SideSwap's system that token was indistinguishable from genuine L-BTC, so its peg-out service — which on Sept. 6 at 14:05 UTC accepted 4,000 L-BTC from a customer, burned them and obtained valid authorization — released about 3,996 BTC on the Bitcoin mainnet roughly 23 minutes later through what appeared to be a routine redemption. The design assumption is simple: 1 BTC locked in mints 1 L-BTC, and 1 L-BTC burned releases 1 BTC. If upstream software mints unbacked tokens, every downstream check still executes correctly — and still pays out real reserves. Before any restart, Blockstream and federation members must complete fixes, resolve the chain split created during the pause, a step that carries replay-attack risk for users, and reconfirm L-BTC's 1:1 backing. Mow has asked users not to send BTC to Liquid peg-in addresses until a safe restart is confirmed.
Restart Hinges on Proven Backing
COINOTAG's reading of the primary evidence is straightforward: the drained amount and the return are both independently verifiable on-chain — exactly 3,400 BTC moved back to the federation address at block 965,950 — and Blockstream's remediation, from patched bridge nodes to signed on-chain confirmation and coordinated restart preparation, addresses the exploit path without fixing the architecture. A system whose keys were never breached still released nearly an entire federation reserve through a valid-looking transaction. Until Blockstream publishes its full Elements vulnerability report and Liquid re-proves L-BTC's 1:1 backing, sidechains in the wider Bitcoin DeFi stack carry a risk class that key-custody audits alone do not capture. On-chain forensics, as seen in efforts like Uppsala Security's INTERPOL gateway work, moved fast here — but this time the counterparties cooperated.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


