Liquid Hack Takes a New Turn as Blockstream Rejects 10% Demand and 598 BTC Remains Missing

Liquid Network hack leaves 598 BTC outstanding as Blockstream rejects ransom demand

By CoinAINews Staff

The $320 million Liquid Network exploit has taken another turn after Blockstream rejected a demand for a 10% payment while roughly 598 BTC remains outstanding.

The development comes after the actors behind the incident returned approximately 3,400 BTC to Liquid's Federation wallet. That represented about 85% of the Bitcoin withdrawn during the attack, but hundreds of millions of dollars worth of crypto remain at the center of the dispute.

The incident began earlier this week when roughly 4,000 BTC was withdrawn from Liquid's Federation wallet. The Bitcoin was worth about $320 million at the time. Liquid subsequently paused parts of its network while Blockstream and other participants worked to identify and fix the underlying vulnerability.

Blockstream Refuses to Pay for the Remaining Bitcoin

The latest dispute is no longer simply about recovering stolen Bitcoin. It is now about whether the people who exploited the vulnerability should receive a financial reward for returning most of the funds.

The actors involved in the incident described themselves as white-hat hackers and returned 3,400 BTC after the affected infrastructure was patched. However, approximately 598 BTC remained under their control.

Blockstream has rejected the idea of paying for the return of the remaining Bitcoin, taking the position that unauthorized removal of assets followed by a demand for compensation should not be treated as a conventional security bounty.

That distinction matters because the crypto industry has long relied on bug bounties and responsible disclosure programs to encourage researchers to report vulnerabilities without exploiting them for personal gain.

About 4,000 BTC Was Pulled From Liquid's Federation Wallet

The scale of the original incident made it one of the most significant crypto security events of September.

Liquid reported that approximately 4,000 BTC had been withdrawn from a Federation wallet that contained roughly 4,200 BTC. Reuters reported the value of the withdrawn Bitcoin at approximately $320 million when the incident occurred.

The withdrawals were processed through SideSwap's settlement infrastructure. Liquid said the cryptographic key used in the process was not compromised, shifting attention toward the software and transaction-processing mechanisms surrounding the system rather than a straightforward private-key theft.

Liquid subsequently disabled bridge nodes and paused new transactions while the security problem was investigated.

Key Detail Reported Figure
Bitcoin withdrawn About 4,000 BTC
Bitcoin held before incident About 4,200 BTC
Estimated value at the time About $320 million
Bitcoin returned 3,400 BTC
Bitcoin still outstanding About 598 BTC

Why Did the Attackers Return 3,400 BTC?

The events following the exploit have made the case unusual.

The attackers contacted Blockstream through messages embedded in Bitcoin transactions and identified themselves as white hats. They indicated that most of the Bitcoin could be returned once the vulnerability had been fixed and the affected network infrastructure had been updated.

After the necessary software changes were made, exactly 3,400 BTC was transferred back to the Liquid Federation wallet. Cointelegraph reported that the returned coins were worth roughly $270 million at the time.

But the recovery stopped short of a full return.

Approximately 598 BTC remained outstanding, leaving Blockstream and Liquid with the difficult task of recovering the remaining funds while dealing with the attackers' demands.

The White-Hat Claim Is Now Being Questioned

Calling the actors “white hats” has become increasingly controversial.

A traditional white-hat security researcher typically identifies a vulnerability, reports it to the affected organization and gives the organization an opportunity to fix the problem. In this case, the actors first removed a huge amount of Bitcoin from the network before negotiating its return.

That difference has led some industry figures to question whether the incident should be described as responsible security research.

Cointelegraph reported that Ledger Chief Technology Officer Charles Guillemet questioned the white-hat characterization, arguing that keeping a large portion of the funds while seeking compensation could look more like extortion than conventional white-hat activity.

For that reason, CoinAINews is using terms such as “actors,” “attackers” and “purported white hats” rather than presenting the white-hat claim as an established fact.

The Real Vulnerability Was Not Bitcoin's Core Blockchain

One of the most important points to understand about the Liquid incident is that Bitcoin itself was not hacked.

The affected system was Liquid, a Bitcoin sidechain and settlement network built around Bitcoin. Liquid uses Bitcoin held by its Federation to support assets issued on the sidechain, including L-BTC.

According to reporting from Liquid and SideSwap, the key involved in the withdrawal was not compromised. SideSwap said the L-BTC involved in the transaction originated from a bug in Elements, the open-source software underpinning Liquid.

This is an important distinction for Bitcoin users. The incident demonstrates a vulnerability in infrastructure built around Bitcoin, not a failure of Bitcoin's base-layer consensus or cryptographic security.

Why the Liquid Exploit Matters for the Wider Crypto Industry

The incident highlights a problem that extends far beyond Liquid.

Modern crypto networks increasingly rely on layers of software that connect blockchains, bridges, exchanges, custodians, sidechains and settlement systems. A weakness in one of those layers can potentially create enormous financial consequences even when the underlying blockchain continues operating normally.

The Liquid incident is a particularly clear example.

The attackers did not need to break Bitcoin's consensus rules. Instead, the exploit affected the infrastructure responsible for handling assets and withdrawals around a Bitcoin sidechain.

For developers, custodians and infrastructure providers, that creates an important lesson: protecting private keys is only one part of blockchain security. The software that validates balances, authorizes transactions and processes withdrawals can be just as critical.

What Happens to the Remaining 598 BTC?

The fate of the remaining Bitcoin is now the biggest unresolved question surrounding the incident.

Blockstream has rejected the demand for payment and is focused on recovering the outstanding funds rather than treating them as a negotiated bounty.

Because Bitcoin transactions are publicly recorded, investigators can monitor the addresses holding the remaining coins and track any subsequent movement. That does not automatically reveal the identity of the people controlling those addresses, but it can provide investigators with a permanent transaction trail.

The longer the 598 BTC remains onchain, the more attention it is likely to receive from blockchain analytics firms, exchanges and law enforcement agencies monitoring the funds.

Liquid Has Already Recovered Most of the Funds

Despite the unresolved dispute, the return of 3,400 BTC significantly changed the situation from the first hours of the attack.

At the beginning of the incident, almost the entire Bitcoin balance of the Federation wallet had been withdrawn. The return of 3,400 BTC restored most of the Bitcoin backing associated with Liquid's system.

Cointelegraph reported that the network had deployed updated software and was preparing for a coordinated restart after the affected infrastructure was patched.

That recovery, however, does not erase the security questions raised by the exploit.

Liquid and the wider Bitcoin infrastructure community will still need to understand exactly how the vulnerability was triggered, why the transaction controls did not prevent the withdrawal and what safeguards can stop a similar incident from happening again.

Could the Liquid Hack Change Crypto Security Practices?

It could.

The case presents an uncomfortable question for the industry: how should companies respond when a security researcher crosses the line between vulnerability discovery and unauthorized asset removal?

If companies pay large rewards after attackers take control of funds, that could create incentives for future exploits. On the other hand, refusing to negotiate can make it harder to recover assets in incidents where attackers are willing to return part of what they took.

The Liquid case therefore sits somewhere between a conventional hack, a vulnerability disclosure dispute and an attempted negotiation over cryptocurrency.

Its final outcome may influence how blockchain companies structure bug-bounty programs, emergency response plans and communication channels with security researchers.

Liquid Hack FAQs

How much Bitcoin was taken from Liquid?

Approximately 4,000 BTC was withdrawn from Liquid's Federation wallet. Reuters reported the value at around $320 million at the time of the incident.

How much Bitcoin was returned?

Exactly 3,400 BTC was returned to the Liquid Federation wallet after the affected infrastructure was patched.

How much Bitcoin is still outstanding?

Approximately 598 BTC remains outstanding, according to reporting following the partial recovery.

Did hackers really call themselves white hats?

Yes. The actors described themselves as white hats in onchain communications. However, that characterization has been disputed, and it should not be treated as an independently established fact.

Was Bitcoin itself hacked?

No. The incident affected the Liquid Bitcoin sidechain and related infrastructure. Reporting has focused on a software vulnerability rather than a compromise of Bitcoin's underlying blockchain.

What is the 10% demand?

The actors involved in the incident sought a 10% payment in connection with the return of the remaining funds. Blockstream rejected the idea of paying for the return of the outstanding Bitcoin.

Bottom Line

The Liquid Network exploit has moved from an enormous Bitcoin withdrawal to a complicated recovery battle.

Roughly 4,000 BTC was initially taken, around 3,400 BTC has since been returned, and approximately 598 BTC remains outstanding.

The most controversial part of the story is no longer simply how the exploit happened. It is what should happen when people who take advantage of a vulnerability later return most of the funds while keeping a substantial amount and seeking compensation.

Blockstream has made its position clear: it does not intend to treat the remaining Bitcoin as a paid security bounty.

For the crypto industry, the Liquid incident is a reminder that security failures do not always require a blockchain itself to be broken. Sidechains, bridges, settlement systems and the software connecting them can create their own critical attack surfaces.

Until the remaining Bitcoin is recovered and the full technical cause of the exploit is understood, the Liquid incident will remain one of the most closely watched crypto security stories of September 2026.

Sources

Disclaimer: This article is for informational purposes only and does not constitute financial, investment, legal or cybersecurity advice.

Post a Comment

0 Comments