Liquid Network Recovers 3,400 BTC After Bridge Exploit, but Nearly $47 Million Remains With Self-Described White Hats
Key Takeaways
- •Actors behind the 4,000 BTC withdrawal returned 3,400 BTC, about 85% of the funds, to the Liquid Federation wallet in block 965,950.
- •Roughly 598.5 BTC, worth about $47 million, remains in the actors' address with no public agreement authorizing its retention.
- •The repayment followed on-chain communications in which Blockstream confirmed its bridge nodes were patched and the actors demanded the fix before returning funds.
- •Liquid's bridge nodes remain disabled and exchanges are still being asked to suspend L-BTC deposits and withdrawals, with no reopening time announced.
- •Ledger CTO Charles Guillemet criticized the white-hat label, arguing the retained funds resemble extortion absent a disclosed bounty agreement.

Liquid Network recovers 3,400 BTC after bridge exploit
The Liquid Network has recovered 3,400 $BTC — worth approximately $269.2 million — from the self-described white-hat hackers behind a 4,000 $BTC withdrawal, although nearly $47 million in Bitcoin remains outstanding.
85% of the withdrawn Bitcoin returned
On-chain data shows that the actors returned 3,400 $BTC, valued at roughly $268.2 million at the time of confirmation, to the Liquid Federation wallet in Bitcoin block 965,950. The transfer recovered about 85% of the withdrawn funds, while 598.5 $BTC, worth roughly $47 million, remained in the actors' address.
Blockstream had previously told the group, via a signed transaction message, that its bridge nodes had been patched and that the funds were "safe to return." The actors have not publicly explained why they retained the remaining coins or indicated whether another repayment will follow.
The incident began on Sunday when a customer sent 4,000 Liquid Bitcoin (L-$BTC) to SideSwap's peg-out service, which allows users to move value from the Liquid sidechain back to the Bitcoin network through an authorized withdrawal process.
The actors later identified themselves as "whitehats" in a message attached to a Bitcoin transaction. White-hat hackers typically find and report security weaknesses so developers can repair them, often receiving a bounty under terms agreed with the affected project. However, no publicly disclosed agreement has established that the Liquid actors had permission to withdraw the funds, and neither Blockstream nor the actors have published terms granting a bounty or allowing the group to retain nearly 600 $BTC.
As crypto.news reported before the return, the actors had offered to send back "most" of the Bitcoin once Blockstream fixed the vulnerability. At that point, no repayment had been confirmed, and the withdrawal represented about 95% of the Bitcoin reportedly held in Liquid's federation wallet.
On-chain messages preceded the 3,400 $BTC repayment
Communication between Blockstream and the actors took place through messages attached to Bitcoin transactions, enabling both sides to exchange instructions without relying on a private messaging service.
In one such message, the actors told Blockstream to repair the flaw before returning the Bitcoin:
"Please fix the bug first," the message read. "The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."
Following that confirmation, the actors sent 3,400 $BTC to the Liquid Federation address. The exchange shows the repayment depended on the actors accepting Blockstream's assurance that the affected nodes were safe, though neither side has released a technical report identifying the flaw or explaining how the withdrawal became possible.
After detecting the transaction, Liquid disabled its bridge nodes and asked exchanges to suspend L-$BTC deposits and withdrawals. The shutdown restricted movement between Liquid and the Bitcoin base layer while developers investigated the incident and applied the patch.
According to Reuters, Blockstream has said the key used during the withdrawal was not compromised. The company has not released a complete post-mortem detailing whether the flaw affected SideSwap, the bridge software, Liquid's Elements codebase, or another part of the peg-out process.
The episode is the latest in a long line of bridge-related security incidents. Cross-chain bridges have repeatedly ranked among the largest crypto losses on record — the Ronin Network breach in 2022 resulted in roughly $600 million in stolen assets, and the Wormhole bridge exploit the same year led to losses of about $325 million — reflecting the systemic risk that custody and message-processing layers introduce when assets are locked on one chain and represented on another.
Ledger CTO questions the white-hat description
Ledger Chief Technology Officer Charles Guillemet challenged the actors' self-description after they returned most of the coins but retained nearly 600 $BTC.
"So, 3,400 $BTC were refunded," Guillemet wrote on X. "The 'white hats' still hold 600 $BTC. If this was ever a negotiated reward under an encrypted contract signed on-chain, it looks more like extortion than white-hat hacking!"
His comment centered on the absence of disclosed terms covering the retained Bitcoin. A conventional bug bounty normally establishes the reward and return conditions before a researcher keeps part of the affected funds, and no comparable agreement between Blockstream and the actors has been made public.
A similar issue arose after the Verus Ethereum bridge exploit in May, when the attacker returned 75% of the stolen funds and kept 1,350 ETH — then worth about $2.8 million — after Verus publicly offered settlement terms. The Liquid repayment differs in that Blockstream has not stated that the remaining 598.5 $BTC constitutes an approved bounty.
White-hat claims alone do not determine an actor's legal status. Any legal assessment would depend on factors such as authorization, the method used to obtain the assets, communications between the parties, and applicable laws. No U.S. regulator or law enforcement agency has announced an action connected to the Liquid withdrawal.
L-$BTC holders await details on backing and withdrawals
Liquid is a federated Bitcoin sidechain developed by Blockstream. Users lock $BTC through its peg system and receive L-$BTC on the sidechain at a one-to-one ratio, enabling faster settlement and asset transfers without routing every transaction across the Bitcoin base layer.
A recent bridge security explainer noted that systems locking assets on one network and issuing corresponding tokens elsewhere depend on the security of their custody, validation, and message-processing systems. Failures at any of those points can interrupt redemptions even when the underlying blockchain continues operating normally.
For U.S.-based users, the immediate issue is operational rather than a change to federal crypto rules. American holders using L-$BTC face the same suspended deposits, withdrawals, and peg services as other users, while native $BTC held directly on the Bitcoin blockchain remains separate from Liquid's sidechain system.
Liquid has not disclosed whether the returned 3,400 $BTC has fully restored backing for the corresponding L-$BTC supply, nor how it plans to handle any gap created by the 598.5 $BTC still controlled by the actors. How the federation addresses any shortfall — whether through recovery of the remaining coins, other reserves, or another mechanism — remains an open question for holders.
No reopening time has been given for the bridge nodes, and exchanges were still being asked to keep L-$BTC deposits and withdrawals suspended. Blockstream has also not published its promised technical account of the flaw or confirmed whether the actors intend to return the remaining Bitcoin.