BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
DarkDotWeb · Sep 9, 2026 · 3 min read · Original story

Liquid Hackers Return 3,400 Bitcoin, Keep $47M

Liquid Hackers Return 3,400 Bitcoin, Keep $47M

Liquid hackers returned 3,400 BTC after exploiting an Elements bug, but 598.5 BTC worth about $47 million remains with the attackers.

Hackers who withdrew nearly 4,000 Bitcoin from the Liquid Network have returned 3,400 BTC, while approximately 598.5 BTC worth around $47 million remains in an address controlled by the attackers.

The funds were taken on September 6 from the federation wallet responsible for holding the Bitcoin backing Liquid’s L-BTC token. The withdrawal was worth roughly $320 million at the time and represented about 95% of Liquid’s reported Bitcoin reserves.

The attackers have described themselves as white-hat hackers and communicated with Blockstream through messages recorded on the Bitcoin blockchain. However, the decision to retain hundreds of millions of dollars in Bitcoin has raised questions about whether the group can reasonably be described as white hats.

The recovered Bitcoin was sent back to a Liquid Federation address at 16:09 UTC on September 7.

The transaction returned exactly 3,400 BTC, representing around 85% of the Bitcoin taken during the incident. The remaining 598.5 BTC was not sent as a separate payment. Instead, it remained as change from the same transaction and was sent back to the address from which the funds had originated.

At a Bitcoin price of approximately $78,000 on September 8, the returned coins were worth about $265 million, while the remaining 598.5 BTC was valued at roughly $47 million.

Neither Blockstream nor Liquid Network has publicly confirmed whether the remaining Bitcoin is part of an agreed reward for identifying the vulnerability.

The incident did not involve attackers stealing one of Liquid’s private keys.

The Bitcoin was withdrawn through SideSwap’s Peg-out Authorization Key, which is used to release Bitcoin from the Liquid sidechain. Blockstream said the key itself was not compromised, and SideSwap likewise said neither its systems nor the authorization key had been breached.

Instead, the issue appears to have originated in Elements, the open-source software used by Liquid.

According to SideSwap, a bug in Elements allowed the L-BTC involved in the withdrawal to be created without the corresponding Bitcoin reserves. Those tokens were then processed through the legitimate peg-out mechanism, resulting in the federation paying out approximately 4,000 BTC on the Bitcoin network.

The exact technical details of the vulnerability have not been publicly disclosed.

After the withdrawal, the attackers began communicating with Blockstream through the Bitcoin blockchain.

An early message associated with the funds identified the actors as “whitehats” and asked Blockstream to contact them. The group subsequently said the vulnerability needed to be fixed and that every relevant node should be patched before the Bitcoin would be returned.

Blockstream later confirmed that its bridge nodes had been patched and sent a signed message indicating that it was safe to return the funds.

The 3,400 BTC was transferred back shortly afterward.

Blockstream has since deployed updated software, while federation members have been preparing for a coordinated restart of the network. As of September 8, however, the incident was still listed as active and Liquid’s public bridge nodes remained offline.

The biggest unanswered question is what will happen to the 598.5 BTC that remains with the attackers.

There is currently no public confirmation that the Bitcoin represents an agreed bounty or reward. Blockstream and Liquid have not stated that such an arrangement exists.

Some security experts have also rejected the white-hat label.

Ledger CTO Charles Guillemet argued that retaining roughly 600 BTC as part of a possible negotiated reward would look more like extortion than responsible vulnerability disclosure.

For now, the situation remains unresolved. Most of the stolen Bitcoin has been recovered, but nearly $47 million remains outside the Liquid Federation’s control.

The incident also highlights a less obvious risk in cryptocurrency infrastructure: a system can suffer a massive loss even when its private keys and authorization systems have not themselves been compromised.

In this case, the attackers appear to have exploited a flaw in the software and then used a legitimate withdrawal mechanism to move the resulting Bitcoin.

Liquid remains paused while its operators work on the recovery and restart process.

Source: The Hacker News

References in this story

  1. SideSwap - Settlement infrastructure of the Liquid Network sideswap.io The most convenient way to hold, send, receive and swap assets on the Liquid Network, a bitcoin sidechain built for securities issuance and trading.
  2. Blockstream: Bitcoin and digital asset infrastructure blockstream.com Blockstream is the global leader in Bitcoin and blockchain technologies, building the foundations for the financial infrastructure of the future.
  3. Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC thehackernews.com Liquid received 3,400 bitcoin back after nearly 4,000 BTC was taken; 598.5 BTC remains unreturned and the network is still paused.

Guides related to this story

← Back to all news