Actors who drained roughly 4,000 Bitcoin from Liquid’s reserves have returned 3,400 BTC to the federation wallet after Blockstream deployed fixes for the software vulnerability linked to the incident. The repayment restores about 85% of the Bitcoin removed from the sidechain’s backing, while approximately 598 BTC remains outside federation control.
The returned Bitcoin was worth about $270 million at the values cited during the incident. Onchain records show that 3,400 BTC was sent back to Liquid’s federation wallet, following messages from the actors saying they would return most of the funds once affected bridge nodes had been patched.
Liquid remains paused while federation members prepare a coordinated restart, according to Blockstream. Samson Mow, chief executive of JAN3, said Blockstream had confirmed the patching of affected nodes and continued communicating with the actors during the shutdown.
Liquid is a Bitcoin sidechain that issues L-BTC, a token designed to be backed by Bitcoin held by its federation. The Sunday withdrawal sharply reduced that reserve: about 4,000 BTC was removed from a wallet that had held roughly 4,200 BTC. The recovery therefore returns most of the collateral supporting L-BTC, although the remaining shortfall leaves the system with less Bitcoin than before the exploit.
Most of the drained reserve has returned
The recovery followed an unusual public negotiation conducted partly through signed messages embedded in Bitcoin transactions. Blockstream contacted the actors through those messages, and the actors responded that they would send funds back after the vulnerability was fixed and every federation node had installed the updated software.
That condition placed the return on operational changes inside Liquid rather than a simple voluntary repayment. Blockstream said updated software had been deployed, while Mow said the federation was also making additional security improvements, resolving a chain split, and preparing systems for the network’s restart.
A chain split occurs when different nodes recognize competing versions of a blockchain’s transaction history. In a federated sidechain such as Liquid, resolving such a split is necessary before normal transfers can resume consistently across the network.
Mow warned users not to send Bitcoin to Liquid peg-in addresses until the restart has been officially confirmed. A peg-in is the process of sending Bitcoin into Liquid in exchange for L-BTC. He said users did not need to take other action while the federation completes recovery work.
The pause limits immediate risks from the affected bridge, but it also leaves L-BTC users waiting for confirmation that deposits, withdrawals, and the sidechain’s normal operations can resume safely.
Elements bug identified as the source
Liquid and SideSwap said the original withdrawal was processed using SideSwap’s Peg-out Authorization Key. A peg-out is the reverse of a peg-in: L-BTC is redeemed and Bitcoin is released from Liquid’s reserve.
SideSwap said its authorization key had not been compromised. Instead, it said the L-BTC used in the withdrawal originated from a bug in Elements, the open-source software that underpins Liquid. Blockstream has developed Elements, which provides the technology used for Liquid’s confidential transactions and federated asset issuance.
That distinction narrows the reported path of the incident. The available statements point to a software flaw affecting the creation or handling of L-BTC rather than the theft of a signing key that directly controlled the federation’s Bitcoin reserve.
It also explains why the actors focused on patches across bridge nodes before returning funds. If a vulnerability remained active on part of the network, a returned balance could potentially remain exposed to another withdrawal attempt.
The episode puts attention on the operational complexity of Bitcoin-linked sidechains. Liquid’s design allows faster and more private transfers than Bitcoin’s base layer, but it also relies on a federation, specialized software, and a peg mechanism that must accurately maintain the relationship between L-BTC in circulation and Bitcoin held in reserve.
Dispute over the “white-hat” description
The actors have been described as white-hat hackers because they returned most of the Bitcoin after the flaw was addressed. That description has drawn criticism because hundreds of Bitcoin remain under their control.
Charles Guillemet, chief technology officer at Ledger, questioned whether the term applies if the actors retain roughly 600 BTC as an apparent reward negotiated through encrypted onchain communications. He said such an arrangement would resemble extortion rather than a conventional security disclosure.
Neither Blockstream nor Liquid has publicly characterized the outstanding Bitcoin as a bounty. They have not disclosed repayment terms, a formal reward agreement, or conditions attached to the approximately 598 BTC that has not returned.
The gap is substantial. At the approximate valuation used in reports of the incident, 598 BTC would represent around $47 million. Leaving that amount unresolved means the recovery cannot yet be treated as a complete restoration of the reserve, even if the majority of the funds have been returned.
White-hat recoveries typically involve a clear disclosure process and a defined return of assets, sometimes followed by a publicly agreed bug bounty. This case unfolded differently: the actors first obtained control of a large share of Liquid’s Bitcoin reserve, then tied repayment to the deployment of fixes, with a portion of the funds still unreturned.
Restart will test Liquid’s recovery process
The next practical test is the federation restart. Blockstream and Liquid will need to restore service while demonstrating that patched nodes are operating consistently and that the peg mechanism can again process Bitcoin deposits and withdrawals without reproducing the flaw.
Users considering a peg-in face a straightforward constraint until that work is complete: Bitcoin sent to a Liquid deposit address should remain unsent until the federation formally confirms the restart. Mow’s warning reflects the fact that a bridge’s safety depends on both its software and the coordinated status of its participating nodes.
The incident did not affect Bitcoin’s base-layer consensus system or Bitcoin wallets outside Liquid’s peg. It instead exposed risks specific to systems that lock Bitcoin on one network and issue a corresponding representation on another.
Liquid’s partial recovery has reduced the immediate reserve deficit dramatically, but the unresolved 598 BTC and the conditions surrounding its possible return will remain central to the fallout. The federation’s restart, its explanation of the Elements vulnerability, and its handling of the remaining funds will determine whether the incident ends as a largely recovered exploit or a lasting shortfall in Liquid’s backing.
To better protect your funds after incidents like this, learn key crypto security practices every trader should know today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
