Key Highlights
- Self-described whitehat hackers have returned 3,400 Bitcoin out of approximately 4,000 BTC taken from Liquid Network’s federation wallet
- Around 598 BTC valued at approximately $47 million remains in the attackers’ possession
- The exploit depleted almost all of Liquid’s 4,200 BTC backing reserves, creating a severe shortfall for L-BTC tokens
- Negotiations between Blockstream and the hackers took place through cryptographically signed messages written into Bitcoin blockchain transactions
- Liquid Network operations continue to be suspended as teams work on security patches, resolve blockchain splits, and plan network reactivation
A significant security breach struck Liquid Network over the weekend, with attackers successfully extracting approximately 4,000 Bitcoin from the federation wallet that serves as backing for the sidechain’s operations. Liquid Network, developed and maintained by Blockstream, uses this federation wallet to provide one-to-one collateralization for L-BTC, its pegged Bitcoin token.
Following the breach, the reserve wallet held merely 197 BTC from its prior balance of approximately 4,200 BTC. This dramatic reduction meant that L-BTC lost its full backing virtually overnight.
Network operators responded with urgency. Bridge node functionality was immediately disabled, all network activity was halted, and cryptocurrency exchanges received requests to suspend L-BTC deposit and withdrawal services. The incident did not impact other digital assets operating on the Liquid platform, such as tether tokens.
The individuals responsible for the breach came forward claiming whitehat status. Their stated intention was to return the stolen cryptocurrency after network operators addressed the security flaw and ensured all nodes had implemented necessary patches.
Blockstream’s team initiated an unconventional communication channel by including cryptographically signed messages within Bitcoin blockchain transactions. Both parties conducted their negotiations in full public view directly on the blockchain.
Majority of Stolen Bitcoin Gets Returned
Following Blockstream’s confirmation that all bridge nodes had received the necessary security updates, the hacker group initiated a transfer of 3,400 Bitcoin back to the federation wallet. This accounts for roughly 85% of the total amount stolen.
Samson Mow, CEO of JAN3 and a former Blockstream executive, verified the return on Monday. He indicated that approximately 598 BTC is still unaccounted for and that discussions with the hacker group are ongoing.
Based on current Bitcoin market valuations, the returned cryptocurrency amounts to roughly $270 million. The portion still retained by the hackers carries an estimated value of $47 million.
The initial withdrawal was executed using SideSwap’s Peg-out Authorization Key mechanism. Representatives from both Liquid Network and SideSwap have clarified that the authorization key itself remained secure and was not breached.
According to SideSwap’s statement, the security vulnerability originated from a software flaw in Elements, the open-source codebase that powers Liquid Network’s infrastructure.
Debate Surrounds “Whitehat” Classification
The classification of these hackers as whitehats has drawn skepticism from some security professionals. Charles Guillemet, chief technology officer at Ledger, expressed reservations following the partial return of funds.
His perspective suggests that if the unreturned 600 BTC represents a negotiated compensation package, the situation resembles extortion more closely than legitimate ethical hacking practices.
Blockstream has refrained from publicly characterizing the outstanding Bitcoin as an official bug bounty payment. Similarly, the company has not revealed any details regarding repayment agreements or terms.
As of Monday, the Liquid Network continues to operate under suspension. Blockstream engineers and federation participants are addressing additional security reinforcements, working to reconcile a chain split issue, and establishing protocols for a synchronized network restart.
Mow advised that users need not take any immediate action. He specifically cautioned against sending Bitcoin to Liquid peg-in addresses until official confirmation of the network’s reactivation has been announced.
Updated software versions have been distributed and implemented. Federation members are now coordinating preparations for a simultaneous restart pending the completion of all necessary preconditions.





