NewsCryptoLiquid Network Hackers Offer to Return $320 Million in Bitcoin, Pending Bug Fix

Liquid Network Hackers Offer to Return $320 Million in Bitcoin, Pending Bug Fix

Author: DailyCoin·

Key Takeaways

  • •Roughly 4,000 bitcoin worth about $320 million were withdrawn from Liquid's federation wallet on September 6, exploiting a software bug in the Elements codebase.
  • •The individuals holding the funds say they will return most of them only after Liquid fixes the vulnerability and patches every network node.
  • •Blockstream and the fund holders are negotiating publicly through OP_RETURN messages embedded in small on-chain Bitcoin transactions.
  • •Liquid has paused new transactions and exchanges have suspended L-BTC deposits and withdrawals while the investigation continues.
  • •The case is nearly 27 times larger than the 2024 Ronin Bridge incident, where a white hat returned about $12 million in funds roughly 80 minutes after the bridge was halted and received a $500,000 bounty.
Liquid Network Hackers Offer to Return $320 Million in Bitcoin, Pending Bug Fix

The individuals holding roughly $320 million in bitcoin drained from Blockstream's Liquid Network say they will return most of the funds — but only after the vulnerability that enabled the exploit is fixed. The negotiation is unfolding publicly, through messages embedded in Bitcoin transactions.

Roughly 4,000 bitcoin were withdrawn from Liquid's federation wallet on September 6, leaving the network facing a software vulnerability and a $320 million hole in its reserves. The two sides are now communicating through small Bitcoin transactions carrying messages that are permanently recorded on-chain.

Liquid Network Hack Drains $320 Million From Federation Wallet

On September 6, roughly 4,000 of the approximately 4,200 bitcoin backing Blockstream's Liquid Network, a Bitcoin-based payments and settlement network, were withdrawn from its federation wallet in a single transfer worth about $320 million at the time by "purported white-hat hackers," according to the company.

We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn 4,000 BTC ($320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message. What we know so far is that the funds… — Liquid Network 🌊 (@Liquid_BTC) September 6, 2026

Blockstream attributed the incident to a software bug in Elements, the open-source codebase underlying Liquid. The funds moved through SideSwap, an approved Liquid trading platform, which reportedly could not distinguish between legitimate and exploit-created coins.

Liquid subsequently halted new transactions while federation members work to resolve the vulnerability and restore normal operations.

The incident highlights a structural feature of Liquid's design: the network is a federated sidechain, meaning users' L-BTC tokens are backed by bitcoin held in a multisignature wallet controlled by a group of functionaries rather than by a Bitcoin smart contract. That makes the integrity of both the federation wallet and the Elements software critical to every L-BTC in circulation, and it explains why exchanges moved quickly to suspend L-BTC deposits and withdrawals once the reserves were compromised.

Hackers Negotiate the Bitcoin Return on the Blockchain

The most unusual part of the incident is what happened next: the alleged white-hat hackers and Blockstream began communicating publicly through OP_RETURN messages embedded in the blockchain, including a discussion over whether returning "most" of the funds would be acceptable.

A white-hat hacker is an ethical hacker who exploits a flaw in a protected system before malicious actors can. They typically exploit a flaw, move the money and seek a fee to return it.

In the Liquid case, the people behind the withdrawal stated that they would return the funds after Liquid fixes the vulnerability. The messages provide a public record of the exchange between the two sides — a transparency that off-chain negotiations, such as those following most large exchange hacks, typically lack.

What the Liquid Network Hack Messages Show

Using tiny "dust" transactions carrying OP_RETURN messages, the two sides have spent the past day negotiating the return of the funds in full public view.

Block 965,822 — A Blockstream-linked address sends 1,000 satoshis to the hacker's wallet with a short message: "Please contact security@blockstream.com."

Block 965,865 — A reply arrives containing an encrypted message and a detached PGP signature corresponding to Blockstream's published security key, providing cryptographic evidence that the message was signed with that key and really came from Blockstream.

Block 965,869 — The hacker responds by spending their own balance, sends 1,000 satoshis to Liquid's federation peg wallet with a message saying: "sending most back to[the federation address], is that ok."

Block 965,875 — A subsequent message attributed to Blockstream says the underlying vulnerability must first be fixed and the network's nodes patched before the funds can safely be returned.

"Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix," the message stated.

A Similar Case: Ronin

The episode has echoes of the 2024 Ronin Bridge incident, when a white-hat MEV searcher exploited a vulnerability and withdrew about 4,000 ETH and $2 million in USDC, worth roughly $12 million at the time.

Ronin stopped the bridge, contacted the operator, and the funds were returned. Ronin said it was negotiating with the actor because they appeared to be white hats acting in good faith. The white hat received a $500,000 bounty.

The process was much faster: the incident occurred, the bridge was stopped, Ronin publicly acknowledged the issue, and the funds were returned about 80 minutes later.

The Liquid case is nearly 27 times larger — and the people holding the funds have made their return conditional on Blockstream fixing the vulnerability and patching the network, while the funds remain in their hands. That condition also makes patching speed a financial issue for Liquid, not just a security one: every day the network remains vulnerable, roughly $320 million in backing assets stays outside the federation's control.

What Happens Next in the Liquid Network Hack

The incident has put Liquid's $320 million reserve problem and its software vulnerability on the same clock.

The network has been paused, and exchanges have suspended L-BTC deposits and withdrawals while the investigation continues.

The negotiation is also unfolding through a channel that is public, timestamped and cryptographically verifiable. The identity of the fund holder, however, remains anonymous — meaning that despite the good-faith signals in the on-chain messages, there is no guarantee the stated intention to return the funds will be carried out, and the outcome will not be known until the vulnerability is fixed and the network's nodes are patched.