Skip to main content
Network Now
BTC Price
Network Hashrate
Difficulty
Next Halving
Back to Blog

Liquid Network Hackers Return 3,400 Bitcoin, But Nearly $47 Million Remains Missing

Liquid Network Hackers Return 3,400 Bitcoin, But Nearly $47 Million Remains Missing

Dominik BoltnarSeptember 8, 20266 min read
Liquid Network Hackers Return 3,400 Bitcoin, But Nearly $47 Million Remains Missing

The situation surrounding the Liquid Network's $320 million Bitcoin exploit has taken an unexpected turn after the attackers returned approximately 3,400 BTC to the network's Federation wallet.

The returned Bitcoin represents roughly 85% of the approximately 4,000 BTC that was removed from Liquid's reserves during the September 6 incident. However, approximately 598.5 BTC, worth around $47 million at the time of reporting, remains in the attackers' possession.

Despite the substantial recovery, the Liquid Network has not yet returned to normal operation.

Nearly 4,000 Bitcoin Were Drained From Liquid

The incident began on September 6 when approximately 4,000 BTC was withdrawn from Liquid's Federation wallet.

Liquid's Federation wallet reportedly held around 4,200 BTC before the incident, meaning the withdrawal represented approximately 95% of the Bitcoin backing the network. At the time, the stolen Bitcoin was worth approximately $320 million.

Liquid is a Bitcoin sidechain that allows Bitcoin to be represented on the network as Liquid Bitcoin, or L-BTC. Bitcoin is locked on the Bitcoin main chain while corresponding L-BTC is issued on Liquid.

The incident therefore posed a serious problem. A huge amount of real Bitcoin had been released from the Federation wallet while the corresponding L-BTC was created through a software vulnerability.

According to reporting from SideSwap and other sources, the affected L-BTC was created because of a bug in Elements, the open-source software that Liquid is built on. The subsequent L-BTC was sent through SideSwap's peg-out service, which ultimately resulted in roughly 4,000 BTC being released from the Federation wallet.

Importantly, Liquid said the SideSwap Peg-out Authorization Key itself was not compromised.

That distinction is significant because it suggests the attackers did not simply steal a private key and use it to empty the wallet. Instead, the incident appears to have involved exploiting a flaw in the software and creating L-BTC that should not have existed in the first place.

The Attackers Said They Were White Hats

Following the exploit, the people responsible began communicating with Blockstream through messages embedded directly into the Bitcoin blockchain.

In one message, the group described itself as white-hat hackers and instructed Liquid to fix the underlying vulnerability before returning the funds.

The attackers reportedly demanded that the vulnerability be fixed and that every relevant node be patched before they would send the Bitcoin back.

Blockstream subsequently sent a PGP-signed message through the Bitcoin blockchain confirming that its bridge nodes had been patched and that the funds could safely be returned.

Not long afterward, the attackers sent 3,400 BTC back to the Liquid Federation wallet.

The transaction was confirmed on the Bitcoin blockchain in block 965,950, providing public and independently verifiable evidence that the majority of the stolen Bitcoin had been returned.

3,400 BTC Is Back, But Nearly $47 Million Is Still Missing

The returned Bitcoin amounted to approximately 3,400 BTC, or about 85% of the total amount withdrawn.

That leaves approximately 598.5 BTC still sitting in an address associated with the attackers. At Bitcoin prices around $78,000, the remaining coins were worth roughly $47 million.

The remaining Bitcoin has become one of the most interesting parts of the incident.

Blockstream and Liquid have continued communicating with the group, but neither organization has publicly disclosed a formal agreement regarding the remaining funds.

That has also led to disagreement over whether the attackers should actually be considered white hats.

Ledger CTO Charles Guillemet questioned the characterization, arguing that if the remaining Bitcoin represents a negotiated reward for returning the funds, the situation begins to look less like traditional white-hat vulnerability disclosure and more like extortion.

For now, there is no public confirmation that the remaining Bitcoin represents a bounty, negotiated payment, or anything else.

What is known is that approximately $47 million worth of Bitcoin remains outside the Federation wallet.

Liquid Remains Paused

Getting the Bitcoin back does not mean the incident is over.

The Liquid Network remains paused while Blockstream and Federation members work through additional security fixes and prepare for a coordinated restart. Bridge nodes have been disabled, while exchanges have paused L-BTC deposits and withdrawals.

Blockstream has reportedly deployed updated software, but the network still needs additional work before normal operations can resume.

Users have also been warned not to send Bitcoin to Liquid peg-in addresses until the network officially restarts.

Other assets issued on Liquid, including assets such as USDT and DePix, have reportedly not been affected by the vulnerability in the same way.

A Major Warning for Bitcoin Infrastructure

The Liquid incident is another reminder that Bitcoin itself can remain secure while applications and infrastructure built around it introduce completely different risks.

The Bitcoin blockchain was not hacked.

Instead, the exploit targeted the software and infrastructure responsible for moving Bitcoin between the Bitcoin network and Liquid.

That distinction is important for anyone using Bitcoin-based networks, sidechains, bridges, exchanges, or other systems that rely on additional software layers.

A user may ultimately be holding an asset backed by Bitcoin, but the security of that asset can still depend on software that exists outside Bitcoin's base layer.

In Liquid's case, the attackers apparently found a way to create L-BTC through an Elements vulnerability and then use a legitimate peg-out process to withdraw the underlying Bitcoin. The result was a massive loss of funds without the underlying cryptographic key being compromised.

What Happens Next?

The immediate priority for Liquid is restoring the network safely rather than rushing to reopen.

Approximately 3,400 BTC has now been recovered, significantly reducing the financial impact of the exploit. However, the remaining 598.5 BTC is still outstanding, and the network itself remains paused while security work continues.

The bigger question is whether Liquid can fully determine how the vulnerability was exploited, ensure every affected node is patched, resolve the chain-related issues reportedly discovered during the response, and restore confidence among users and exchanges.

For Bitcoin users, the incident also highlights an important distinction that can sometimes get lost in the broader crypto ecosystem.

Bitcoin's base layer may be extremely difficult to compromise, but that does not automatically make every system built around Bitcoin equally secure.

Liquid's $320 million incident demonstrates how a vulnerability several layers above Bitcoin can ultimately put hundreds of millions of dollars worth of real Bitcoin at risk.

For now, most of that Bitcoin is back.

But until the remaining funds are recovered and Liquid safely resumes operations, the incident is far from finished.

Share
Dominik Boltnar
Writer at Endless Mining

Stay Updated

Fresh guides and market signal in your inbox. No spam, unsubscribe anytime.

Comments (0)

No comments yet — be the first to share your thoughts!

Log in to leave a comment.

Liquid Network Hackers Return 3,400 Bitcoin, But Nearly $47 Million Remains Missing | Endless Mining Blog | Endless Mining