The purported white-hat hackers who withdrew approximately 3,998.5 BTC from Liquid Network's federation wallet on September 6 returned 3,400 BTC to the federation address in block 965,950 after Blockstream confirmed its bridge nodes had been patched. About 598.5 BTC worth approximately $47.3 million remains in the attacker's wallet. Liquid Network stays paused while Blockstream and federation members make additional fixes, resolve a chain split, and prepare a coordinated restart.
JAN3 CEO and former Blockstream executive Samson Mow published the update on X.
"The network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart," Mow wrote, adding that users should not send Bitcoin to Liquid peg-in addresses until the network's restart is confirmed.
Update: 3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the @Liquid_BTC Federation wallet. The return followed confirmation from @Blockstream that the affected bridge nodes have been patched. Approximately 598 BTC remains outstanding, and…
— Samson Mow (@Excellion) September 7, 2026
What the Elements bug actually allowed
SideSwap, whose Peg-out Authorization Key was used to process the original withdrawal, clarified its role in the incident. The service said the transaction involved 4,000 LBTC sent to its peg-out service, which burned the tokens using a valid authorization before the Liquid Federation paid 3,996 BTC to the customer's Bitcoin address. Blockstream subsequently established that the LBTC had been created through a bug in Elements, the open-source software underpinning Liquid. SideSwap said neither its systems nor its peg-out authorization key had been compromised.
Elements is the open-source blockchain platform Blockstream developed as the foundation for Liquid. It extends Bitcoin's codebase with features including confidential transactions, which hide transfer amounts using cryptographic commitments, and asset issuance, which allows tokens other than BTC to be created and transferred on the network. A bug in Elements at the LBTC creation layer would mean an attacker could create LBTC without a corresponding BTC deposit backing it, effectively minting unbacked tokens that could then be redeemed through the legitimate peg-out process. That mechanism would explain how funds left the federation wallet without the SideSwap PAK itself being compromised. The attacker did not steal a key. They exploited a vulnerability that allowed them to generate valid claims against the federation's real BTC reserves.
How Blockstream's patch confirmation triggered the return
The onchain negotiation had been explicit about the condition for return. In block 965,875, the white-hats wrote:
"Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."
That message contained technical details encrypted to Blockstream's published PGP key, readable only by Blockstream.
After Blockstream deployed updated software across bridge nodes, it sent a PGP-signed onchain message stating that bridge nodes were patched and it was safe to return the funds. The signature verified against the security key published on Blockstream's website. The return of 3,400 BTC followed in block 965,950.
The use of PGP-signed messages in Bitcoin transactions for this negotiation has no direct precedent at this scale. PGP, or Pretty Good Privacy, is an encryption standard developed by Phil Zimmermann in 1991 that allows parties to sign and encrypt messages using public-private key pairs. Blockstream maintains a publicly verifiable PGP key at blockstream.com/pgp.txt. By encrypting technical vulnerability details to that specific key, the white-hats ensured only Blockstream could read the exploit mechanics while the fact of the communication remained visible to anyone monitoring the Bitcoin blockchain. That combination served two purposes: it gave Blockstream the information needed to patch without making the exploit details public while the network remained vulnerable, and it created an auditable record of good-faith engagement that protected the white-hats from later accusations of pure theft.
Whether 598 BTC remaining constitutes a bounty or extortion
Ledger chief technology officer Charles Guillemet raised a specific objection to the white-hat characterization after the partial return. He said that if the approximately 600 BTC still under their control represented a reward negotiated through encrypted onchain communications, the arrangement looked "more like extortion than white-hat hacking."
Neither Blockstream nor Liquid publicly described the outstanding Bitcoin as a bounty or disclosed any repayment terms. The distinction matters legally and reputationally. A white-hat disclosure typically involves reporting a vulnerability to the affected party without extracting funds, or in some bug bounty programs, receiving a pre-agreed reward after responsible disclosure. The Liquid situation involved the actual removal of funds first, the disclosure of the bug second, and a conditional return third.
The Poly Network comparison is instructive but imperfect. When a hacker drained over $600 million across Ethereum, Binance Smart Chain, and Polygon in August 2021, the attacker eventually returned all funds and received a $500,000 bug bounty from Poly Network along with a job offer. That situation involved a trustless cross-chain bridge rather than a federated sidechain, and the attacker communicated willingness to return funds almost immediately after the exploit. Liquid's case involves a federated system where Blockstream retains administrative control, a multi-day negotiation conducted entirely on-chain, and a partial return that leaves a significant amount outstanding with no publicly disclosed terms governing the remainder.
Blockstream continues to engage with the white-hat hackers over the outstanding 598.5 BTC. Liquid remains fully paused with no confirmed restart timeline published at the time of writing.

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.





