Skip to main content
Liquid NetworkSecurity Exploit· 4 min read· in Finance

Liquid Network Hackers Return 3,400 Bitcoin but Retain $47 Million as 'White-Hat' Bounty

Attackers who drained $320 million from the Liquid Network returned 85% of the funds after a software patch, sparking debate over whether their $47 million retention constitutes a bug bounty or extortion.

By Andre Figueira

Security Skeptics 45%Federated Network Critics 35%White-Hat Advocates 20%
Security Skeptics
Contend that keeping $47 million constitutes extortion, regardless of the returned funds.
Federated Network Critics
Point to the 95% reserve drain as proof that sidechains carry unacceptable counterparty risk.
White-Hat Advocates
Argue the hackers secured the network by forcing a patch and returning 85% of the funds.

Perspectives this story doesn't cover

  • Retail L-BTC Holders
  • SideSwap Operators

Why this matters

The breach exposes the distinct counterparty risks of federated sidechains, demonstrating that even when cryptographic keys remain secure, software bugs can instantly drain hundreds of millions of dollars from institutional crypto reserves.

A self-described "white-hat" hacking group insists it drained 4,000 Bitcoin—worth $320 million—from the Liquid Network to force a critical security patch, returning 3,400 BTC once the vulnerability was closed. Cybersecurity analysts and network operators, however, point to the 598.5 Bitcoin that the attackers retained as a self-declared $47 million bounty, arguing that a 15% withholding crosses the line from responsible disclosure into extortion. The debate centers on whether the return of the majority of the funds justifies the retention of a massive payout, setting a complex precedent for how decentralized networks handle catastrophic exploits.[2][3][5]

The September 6, 2026, breach removed 95% of the sidechain's total Bitcoin reserves in a single transaction, leaving the federation wallet with a fraction of its former holdings. For institutional traders and retail users holding L-BTC—a token designed to be backed one-to-one by Bitcoin on the base layer—the drain temporarily reduced the backing of their assets to pennies on the dollar. This severe undercollateralization forced major cryptocurrency exchanges to immediately freeze L-BTC deposits and withdrawals, while the network operators paused all sidechain operations to prevent any further hemorrhaging of funds and to assess the scope of the vulnerability.[3][5]

The unauthorized withdrawal did not rely on stolen private keys or a conventional phishing attack. Instead, the attackers exploited a cache-key collision vulnerability in Elements, the open-source software underlying the Liquid Network. This flaw allowed them to mint 4,000 unbacked L-BTC out of thin air and process it through SideSwap's Peg-out Authorization Key (PAK). Because the transaction appeared valid under the buggy consensus rules, it tricked the federation's 11-of-15 multisignature wallet into releasing real Bitcoin to an external address without compromising the keys themselves.[2][3][4][5]

The attackers returned 85% of the stolen Bitcoin but retained a $47 million bounty.

Immediately following the withdrawal, the attackers embedded a message in the Bitcoin blockchain's OP_RETURN field, stating clearly, "we are whitehats. contact us on chain." Blockstream, the primary developer behind the Liquid Network, responded via PGP-encrypted messages, initiating a highly public negotiation visible on the distributed ledger. The attackers demanded that every bridge node be patched against the Elements software bug before any funds would be returned, effectively framing the $320 million theft as a forced security audit rather than a malicious heist. This unconventional communication method underscored the transparency of blockchain networks even during active security crises.[1][5][6]

Immediately following the withdrawal, the attackers embedded a message in the Bitcoin blockchain's OP_RETURN field, stating clearly, "we are whitehats.

On September 7, 2026, after Blockstream confirmed the deployment of updated software to close the vulnerability, the attackers initiated a transaction at 16:09 UTC. They sent 3,400 BTC back to the Liquid Federation's wallet, restoring 85% of the stolen reserves. The remaining 598.5 BTC was routed to a change address controlled by the attackers, where it currently sits unmoved. Neither Blockstream nor the Liquid Network has publicly confirmed whether this retained amount represents an agreed-upon settlement or an ongoing dispute.[5][6]

The Liquid Network remains paused as federation members coordinate a safe restart and work to resolve a resulting chain split caused by the emergency halt. While the return of the 3,400 BTC averts a total collapse of the sidechain's peg, the missing $47 million leaves a significant hole in the reserve that must be addressed before normal operations can resume. Blockstream continues to communicate with the attackers, navigating the delicate balance between recovering the remaining funds and restoring operational normalcy for users whose assets remain frozen on the sidechain during the ongoing outage.[2][3][6]

Liquid Network Bitcoin reserves plummeted before the partial return of funds.

The incident strictly isolates the risk to the sidechain infrastructure; the Bitcoin base layer and its underlying consensus rules were entirely unaffected by the exploit. However, the breach vividly highlights the distinct counterparty risks inherent in federated networks. Users of these sidechains rely on a consortium of operators and complex bridge software rather than the decentralized security of the main blockchain. This architecture exposes them to software bugs that can drain reserves even when cryptographic keys remain perfectly secure, challenging the assumption that sidechains inherit the full security profile of the base layer.[3][4][5]

As cryptocurrency exchanges wait for the official all-clear to resume L-BTC trading, the immediate focus shifts to how the Liquid Federation will recapitalize the missing 598.5 Bitcoin. The network must now demonstrate whether it can absorb a $47 million shortfall without permanently impairing the one-to-one peg that underpins its core utility. Until the reserves are fully restored or the attackers voluntarily return the balance, the sidechain effectively operates with a fractional backing, testing the broader market's tolerance for federated security models in high-value digital asset infrastructure.[2][6]

Viewpoints in depth

White-Hat Advocates

Some observers argue the attackers performed a necessary, albeit extreme, security service.

Proponents of this view emphasize that the attackers returned 3,400 BTC—the vast majority of the stolen funds—once Blockstream patched the vulnerability. They argue that in the decentralized finance space, where malicious actors frequently drain entire protocols without returning a single cent, a 15% retention functions as a de facto bug bounty. From this perspective, the forced exploit was the only way to ensure the critical Elements bug was patched before a truly malicious actor could permanently destroy the network.

Security Skeptics

Cybersecurity professionals contend that retaining $47 million invalidates any white-hat claims.

Critics argue that responsible disclosure involves reporting a bug privately and allowing developers time to fix it, not draining $320 million from a live network. By withholding 598.5 BTC, the attackers crossed the line from security research into extortion. Security analysts note that a $47 million 'bounty' is unprecedented and non-consensual, setting a dangerous precedent that encourages future attackers to hold networks hostage under the guise of providing a security service.

Federated Network Critics

Blockchain purists view the breach as a fundamental failure of federated sidechain models.

For critics of sidechains, the Liquid Network hack illustrates the inherent dangers of moving assets off the main Bitcoin blockchain. Because Liquid relies on a federation of 15 functionaries and complex bridge software, it introduces counterparty risk and smart contract vulnerabilities that do not exist on the base layer. These critics argue that the 95% drain of Liquid's reserves proves that federated models cannot offer the same security guarantees as decentralized consensus, regardless of how securely the cryptographic keys are managed.

Key points

  • Attackers drained roughly 4,000 Bitcoin ($320 million) from the Liquid Network on September 6, 2026.
  • The exploit utilized a cache-key collision bug in the Elements software, not stolen private keys.
  • The attackers returned 3,400 BTC on September 7 after Blockstream patched the vulnerability.
  • Approximately 598.5 BTC ($47 million) remains under the attackers' control as a self-declared bounty.
  • The Liquid Network remains paused as operators coordinate a safe restart and recapitalization.

How we got here

  1. Sept 6, 2026

    Attackers exploit an Elements software bug to drain 4,000 BTC from the Liquid Federation wallet.

  2. Sept 6, 2026

    Attackers post an on-chain message claiming to be white-hat hackers demanding a patch.

  3. Sept 7, 2026

    Blockstream deploys a patch to the affected bridge nodes.

  4. Sept 7, 2026

    Attackers return 3,400 BTC, retaining 598.5 BTC as a self-declared bounty.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Security Skeptics 45%Federated Network Critics 35%White-Hat Advocates 20%
  1. [1]edgeX ExchangeWhite-Hat Advocates

    Alleged White-Hat Hackers Withdraw 4,000 Bitcoin From Blockstream's Liquid Network Federation Reserves

    Read on edgeX Exchange
  2. [2]SecurityWeekSecurity Skeptics

    Hackers Return $263 Million Stolen From Liquid Network

    Read on SecurityWeek
  3. [3]eSecurity PlanetFederated Network Critics

    Liquid Network Hackers Return Most of $320M Bitcoin Haul

    Read on eSecurity Planet
  4. [4]Halborn

    Explained: The Liquid Network Hack (September 2026)

    Read on Halborn
  5. [5]247WallStFederated Network Critics

    Attackers Drained 4,000 Bitcoin From Blockstream's Liquid Network. They Say They Are White Hats and Want to Give It Back.

    Read on 247WallSt
  6. [6]The Hacker NewsSecurity Skeptics

    Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

    Read on The Hacker News

Comments

Stay informed

Every angle. Every day.

Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.