Liquid Network Hacker Returns 3,400 Bitcoin, Keeps $47 Million After Blockstream Patches Bug

Blockstream's Liquid Network spent the first weekend of September at the center of Bitcoin's newest security scare, and by Monday most of the money was already back where it started.
A self-described white hat drained nearly all of the Bitcoin sitting in Liquid's federation wallet, the reserve that backs Liquid Bitcoin (L-BTC) one to one. Purported white-hat hackers withdrew about 4,000 of the 4,200 bitcoin held in Liquid Network's federation wallet, prompting the Bitcoin sidechain to halt new transactions. The coins, worth roughly $320 million at the time, moved out through SideSwap, a peg-out service that the network treats as approved and trusted.
HOW THE BUG WORKED
Liquid uses confidential transactions to hide amounts for privacy, which normally requires nodes to check a "range proof" confirming that a hidden output is a real, positive number. To save on computation, nodes cache the result of a range proof they have already verified under a label called a cache key. The flaw sat in how that cache key was built: an attacker could get a valid one-for-one transaction cached under the same key as a fraudulent transaction minting thousands of extra L-BTC, and the node would wave the second one through because it recognized the key rather than re-checking the math. The vulnerability appears to have originated in Elements, the Bitcoin Core fork used by Liquid, where a range-proof verification cache bug apparently enabled the creation of L-BTC without the Bitcoin normally required to back it.
The attacker then cashed the inflated L-BTC out for real bitcoin on the base chain. Blockstream attributed the incident to a software bug in Elements rather than compromised keys, with the affected funds moving through the approved SideSwap trading platform, and later determined that a software bug had created some of the bitcoin involved in the system. SideSwap said it couldn't tell which coins came from the bug and which were real, so it treated them all the same.
THE NEGOTIATION, ON CHAIN
Instead of going quiet, the attacker left an OP_RETURN message on the Bitcoin blockchain claiming to be a white hat and asking Blockstream to make contact on chain rather than by email. What followed was a back and forth conducted entirely in Bitcoin transaction data and PGP-signed messages, with the attacker refusing to send the money back until Blockstream confirmed every node had been patched. In a message at block 965,875, the party told Blockstream to fix the bug first and ensure every node is patched before transferring the funds back, and Adam Back-led Blockstream subsequently sent a PGP-signed onchain message saying bridge nodes are patched and safe to return the funds.
MOST OF THE MONEY CAME BACK
Once Blockstream confirmed the patch, the attacker moved. After Blockstream told the actors its bridge nodes had been patched, and the funds were safe to return, they broadcast a transaction sending 3,400 BTC to the federation address. That left a smaller pile behind. About 598 BTC, or 15% of the consolidated pile, stayed at the same holder address as an implied bounty fee worth 48 million dollars. No public agreement on a bounty has surfaced, so whether that remainder is a negotiated fee or simply what the attacker chose to keep is not confirmed.
Not everyone in Bitcoin security circles is buying the white hat framing. Ledger CTO Charles Guillemet argued that attackers disclose a flaw before moving hundreds of millions in collateral, saying white hats don't drain a bridge and then solicit an on-chain contact, and compared it to the Ronin bridge hack and the Euler Finance attacker's later negotiation.
WHY THE TIMING STANDS OUT
This is the second Bitcoin-adjacent exploit in about five weeks, after hackers drained more than $130 million from Coldcard hardware wallet users starting July 30 by exploiting a firmware flaw that made seed generation predictable. It also landed just days after OpenAI began rolling out GPT-6 Astra, a model the company itself flagged for advanced cybersecurity capability. OpenAI describes Astra as its most capable model broadly deployed and its first model to reach the Critical cybersecurity capability threshold under the Preparedness Framework. Simply Bitcoin's hosts pointed to that overlap on the show, arguing that both good-faith researchers and bad actors are increasingly using frontier AI models to comb through Bitcoin's critical infrastructure code for exploitable bugs, not just on Bitcoin but across traditional finance as well.
WHAT IT DOES NOT CHANGE
None of this touches Bitcoin's base layer. Liquid is a federated sidechain that Blockstream built on top of Bitcoin, and the bug lived in Liquid's own Elements software, not in Bitcoin's protocol. Bitcoin's price barely reacted to any of it. BTC price remained stable near $80,000 through the exploit and the return. Liquid itself is the part still recovering: the sidechain remains paused while operators work to restore full 1:1 backing for L-BTC, and roughly $47 million sits in an attacker's wallet with no public word on whether it was ever meant to stay there.
This story comes from the Simply Bitcoin Live show. Watch the full episode.



