Key Takeaways:
- Hackers returned 3,400 BTC worth $268M after Blockstream patched the Elements bug
- Roughly 598.5 BTC ($47M) remains under actors' control with no bounty agreement
- Network stays paused as operators work to restore 1:1 L-BTC backing
Key Takeaways:

Self-described white-hat hackers returned 3,400 BTC worth about $268 million to Liquid Network on Sept. 7, while retaining roughly 598.5 BTC valued at $47 million.
"Please fix the bug first. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix," the actors wrote in Bitcoin OP_RETURN messages to Blockstream, which operates the Liquid sidechain.
The return follows a Sept. 6 exploit that drained nearly 4,000 BTC — about 95 percent of the federation wallet's 4,200 BTC reserve — through a range-proof verification cache bug in Elements, the Bitcoin Core fork powering Liquid. Blockstream patched bridge nodes before the actors broadcast the return transaction. No federation keys were compromised, and SideSwap said its Peg-out Authorization Key was not breached.
The network remains paused as of Sept. 7, with bridge nodes disabled and L-BTC deposits and withdrawals halted at centralized exchanges. Liquid must prove legitimate L-BTC is again backed 1:1 and distribute a patched Elements release before reopening the bridge. The roughly 598.5 BTC still under the actors' control — with no published agreement on whether it constitutes a bounty — leaves a $47 million hole in the reserve.
The actors first conducted a 2.5 BTC dry run before roughly 4,000 L-BTC reached SideSwap's peg-out service at 14:05 UTC. SideSwap processed the request normally, burning the L-BTC and requesting payment, and Liquid's federation sent 3,996 BTC to the destination at 14:28 UTC. The failure occurred at the issuance layer — unbacked L-BTC entered the system — rather than at the custody layer.
Galaxy Digital research head Alex Thorn said the actors sent encrypted technical details to Blockstream to help locate and fix the vulnerability. Ledger CTO Charles Guillemet questioned the take-first-and-negotiate-later approach, though he later acknowledged the actors could be inexperienced researchers. Liquid itself has cautiously called them "purported white-hat hackers."
Other assets on Liquid, including USDT, DePix, and real-world assets, were not touched. Bitcoin's main network was unaffected, and Liquid wallets such as Aqua are disrupted only for their Liquid functionality. The actors' address retains 598.49955894 BTC, with no published agreement explaining whether those funds will eventually return.
A restart may be in the cards once operators can prove legitimate L-BTC is again backed 1:1, distribute a patched Elements release across the network, and decide it is safe to reopen the bridge. Until those steps are complete, the roughly $47 million in retained funds remains an unresolved liability for the federation's 80-plus member exchanges and asset managers.
This article is for informational purposes only and does not constitute investment advice.