Liquid Network Recovers 3,400 BTC After On-Chain Negotiations; White Hats Retain 598.5 BTC Bounty
Key Takeaways
- •The white hat party returned 3,400 of the roughly 4,000 BTC taken from the Liquid Network, keeping 598.5 BTC (about 15%) as an implied bounty worth approximately $48 million.
- •Negotiations were conducted through messages embedded in Bitcoin transactions, with the white hats requiring Blockstream to patch an Elements software bug before returning the funds.
- •SideSwap stated the original withdrawal exploited an Elements bug, a flaw relevant to other operators running Elements-based sidechains.
- •Blockstream exchanged encrypted on-chain messages after the return, and a sad-face emoji from the white hats suggested negotiations over reducing the bounty did not succeed.
- •Blockstream and Liquid have made no public statement on the return, and the fate of the retained BTC and the network's resumption remain unresolved.

The self-described "white hat" party that withdrew nearly 4,000 bitcoin from the Liquid Network federation wallet on Sunday returned 3,400 BTC to the wallet on Monday. Roughly 598 BTC — 15% of the consolidated pile — remained at the same holder address as an implied bounty fee worth approximately $48 million.
The Liquid Network is a Bitcoin sidechain developed by Blockstream that uses a federation of functionaries, rather than Bitcoin's proof-of-work mining, to validate blocks and manage the multisignature peg that holds BTC backing the network's L-BTC asset. That federated model means the security of pegged funds depends on both the honesty of functionary keys and the correctness of the underlying Elements software — the latter being what the white hats cited in their messages.
The return transaction (bc49a46d) was confirmed at 16:09 UTC on September 7. It returned exactly 3,400 BTC to the labeled Liquid peg script address and sent the 598.5 BTC change back to the "white hat" address.
A Day of On-Chain Negotiations
The transfer followed a day of messages written directly into Bitcoin blocks — a communication method in which arbitrary data embedded in transactions becomes permanently visible to anyone, offering both parties a tamper-proof public channel when no off-chain contact existed. The white hats first published an on-chain transaction with a message in the OP_RETURN arbitrary data field reading "contact us on chain"; the message originated from the address holding the 4,000 BTC taken from the Liquid Network.
A Blockstream-linked address responded with "Please contact security@blockstream.com." Later notes from that sender carried Electrum-encrypted payloads and PGP signatures that can be verified against Blockstream's published security key.
In block 965869, the white hats asked in clear text whether sending "most" of the funds back to the federation script was acceptable; the 1,000-sat output on that transaction served only as a message carrier.
Soon after, the white hats wrote: "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix," followed by an encrypted message encrypted to Blockstream's PGP key.
In the same block, a clear-signed reply from the Blockstream sender said "Yes, thank you." Hours later, the same Blockstream-linked address posted another clear-text note: "Bridge nodes are patched, safe to return the funds."
An 85/15 Split
Minutes after the 3,400 BTC landed, the white hats had sent back 85% of the funds, keeping 15% as an implied finder's fee. The choice was celebrated by some on X as "better than keeping 100%," while others were taken aback by the amount. While 15% might sound proportionate — in line with percentages sometimes negotiated in crypto incident-response bug bounties — the total sum is so large that it nears $50 million at current prices.
Blockstream appeared displeased with the finder's fee: four encrypted messages followed on-chain a few hours later — likely after the immediate fires had been put out and the lawyers had a chance to weigh in. An hour later, one more encrypted message was posted from Blockstream. The white hats replied with two encrypted messages, and Blockstream replied once an hour later. The white hats then published a simple yet meaningful sad-face emoji, suggesting negotiations over reducing the size of the bounty did not go well.
The contents of those encrypted messages are unknown, and Blockstream has made no public statements on the matter. The full chat can be followed on a dedicated site built by the author. Other researchers tracking the conversation and on-chain data include Sjors's GitHub gist and Alex Thorn of Galaxy Research on X.
Official Statements
Liquid's Sunday statement remains the network's last official account post: purported white hats withdrew about 4,000 BTC through the SideSwap peg-out path, the PAK itself was not compromised, other issued assets were unaffected, and the sidechain was paused. Liquid and Blockstream had not posted a new statement on the 3,400 BTC return as of this writing. SideSwap had said the L-BTC in the original peg-out "came from an Elements bug." Elements is the open-source codebase, derived from Bitcoin Core, on which Liquid is built — meaning the reported flaw would be relevant to other operators running Elements-based sidechains as well.
What remains unresolved is the fate of the retained 598.5 BTC, whether Liquid resumes full operation, and whether any further official accounting of the incident will be published.
This article first appeared on Bitcoin Magazine and was written by Juan Galt.