Skip to main content

Crypto Club

M Still Missing After Liquid Hack as Blockstream Bargains With ‘White Hats’

$47M Still Missing After Liquid Hack as Blockstream Bargains With ‘White Hats’

🔐 A Partial Return, Not A Resolution

The most important number in the Liquid Network incident is no longer the roughly 4,000 BTC originally withdrawn. It is the 598.5 BTC that had not returned as of the latest reported status. An unknown party sent 3,400 BTC back to a Liquid Federation address after Blockstream said bridge nodes had been patched, according to The Block’s account of the return. That is about 85% of the bitcoin involved, but it still leaves an amount reported around $47 million outside the federation’s control. The party described itself, or was described in coverage, as a “white hat.” That label should be treated as a claim, not a conclusion. A recovery is meaningful, but it does not erase the unauthorized withdrawal, settle responsibility, or restore normal service. For users and investors watching crypto infrastructure, the useful frame is partial remediation under pressure, not a clean security success.


🧩 What The Incident Appears To Involve

Liquid is a Bitcoin sidechain operated through a federation, designed to support assets such as LBTC and services including peg-ins and peg-outs between the sidechain and Bitcoin. The reported sequence centers on nearly 4,000 LBTC entering SideSwap’s peg-out path, being burned under a valid authorization, and roughly 3,996 BTC then being paid to a Bitcoin address. Cointelegraph’s reporting on the operational pause and The Block both describe a bug in the Elements software as the underlying issue reported by SideSwap, rather than a compromise of SideSwap’s peg-out authorization key. That distinction matters, but it should not be read as a final forensic ruling. A working authorization can still be used in a flow where another component has failed. The practical result was the same for the network: bitcoin left the federation wallet and the bridge-facing system was disrupted while parties worked through a response.


📬 Onchain Messages Became The Negotiation Channel

This was not a conventional post-exploit recovery with a public bounty page and a signed settlement. Reporting describes communication through Bitcoin OP_RETURN messages and PGP-encrypted text. The party holding the funds said Blockstream needed to fix the bug and patch every node before a return. Blockstream then sent a PGP-signed onchain message saying bridge nodes were patched and it was safe to return the bitcoin, after which 3,400 BTC moved back. Unchained’s report on the retained balance likewise places the unresolved amount near 600 BTC. The spectacle of an attacker setting technical conditions is a reminder that onchain traceability does not automatically create control. It can provide a public negotiation rail, but it does not make a counterparty trustworthy. Until the remaining balance and the full remediation are independently settled, the messages are evidence of an ongoing dispute, not proof of benevolent intent.


⏸️ The Bridge Was Still The Immediate Constraint

The return did not mean the network could simply resume. Liquid had paused network activity, disabled bridge nodes, and exchanges were asked to suspend LBTC deposits and withdrawals. SideSwap said swaps, peg-ins, and peg-outs would remain paused until the network resumes, as summarized in the updated operational report. That status is critical because a sidechain’s utility depends on more than its token balance. Users need confidence that the mechanisms connecting assets, counterparties, and settlement will behave as expected. It would be premature to claim a restart, or to assume that a patch announcement alone restores that confidence. A resumed service, if and when it occurs, will need to be judged by its actual operating state, the clarity of the incident review, and whether counterparties restore support. Pausing the bridge was a containment action, not the final chapter.


🛠️ A Federation Still Has Operational Risk

Bitcoin-adjacent infrastructure often gets discussed as if its security properties are inherited automatically from Bitcoin itself. This incident is a sharper illustration of where the boundaries are. Liquid’s federation, the Elements software, bridge nodes, peg-out process, exchange integrations, and third-party services create an operational stack with its own assumptions. The report that the key itself was not compromised may narrow one theory of failure, but it also emphasizes the need to understand the surrounding software and process controls. The Hacker News’ coverage underscores the scale of the return while documenting the unresolved balance. For users, the lesson is not that federated designs are uniquely unsafe. It is that custody and bridge risk live in the full system, including software defects and incident response. “Bitcoin sidechain” is architecture, not a blanket insurance policy against implementation mistakes.


📊 What To Watch Before Drawing A Conclusion

The next developments should be concrete: confirmation of the final BTC balance, a clear account of what was fixed, the conditions for restoring bridge functions, and evidence that normal peg activity is actually available again. Users with LBTC exposure should watch the status of deposits, withdrawals, swaps, peg-ins, and peg-outs rather than relying on headlines about the returned 3,400 BTC. Investors should also separate recovery optics from residual risk. The return reduced the immediate shortfall, but it did not make the missing roughly 598 BTC disappear or turn a self-applied “white hat” label into verified motivation. The canonical Decrypt report on the $47 million still missing captures the central unresolved point: Blockstream was negotiating while material funds remained outside the federation. This is a story about resilience being tested in real time. The eventual measure is a full, verified recovery and a stable service, not the first large transaction back.


Sources

https://decrypt.co/377723/liquid-hack-47m-blockstream-bargains-white-hat
https://www.theblock.co/news/defi/2026-09-07-liquid-network-attacker-says-they-will-return-most-of-4000-btc-after-bug-fix-413673
https://cointelegraph.com/news/liquid-white-hats-return-270m-bitcoin-network-restart

Liquid Attackers Return 3,400 BTC and Keep Nearly 600 as Blockstream Prepares a Restart


https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html


Crypto Club and Mode Mobile communications are for informational purposes only, and are not a recommendation, solicitation, or research report relating to any investment strategy, security, or digital asset. All investments involve risk including the loss of principal and past performance does not guarantee future results.

Any information contained in this commentary does not purport to be a complete description of the securities, markets, or developments referred to in this material. The information has been obtained from sources considered to be reliable, but we do not guarantee that the foregoing material is accurate or complete. There is no guarantee that any statements or opinions provided herein will prove to be correct.


Get fresh insights, breaking news, and hidden gems in the world of crypto—delivered straight to your inbox with our Crypto Cookies newsletter.

Don’t miss out—sign up now and get your first bite of insider knowledge!

Related Articles

Sponsored