Liquid Network has recovered 3,400 BTC from the actors behind a 4,000 BTC withdrawal that disrupted its bridge system, restoring about 85% of the Bitcoin removed during the incident. The returned funds were worth roughly $268 million when the repayment was confirmed, while approximately 598.5 BTC, valued near $47 million, remained in the withdrawal-linked address.
The recovery followed an unusual sequence of on-chain communication between Blockstream and the actors, who described themselves as “whitehats.” Before sending the majority of the Bitcoin back, they told Blockstream to patch the affected bridge nodes and confirm that the vulnerability had been fixed. Blockstream later sent a signed transaction message stating that the nodes were patched and that the funds were “safe to return.”
The actors then transferred 3,400 BTC to the Liquid Federation wallet in Bitcoin block 965,950. The transaction significantly reduced the size of the loss, but it did not close the incident. Nearly 600 BTC remain outside the federation’s control, no technical post-mortem has yet been published, and Liquid has not announced when its bridge and L-BTC services will return to normal operation.
The incident began with a 4,000 L-BTC peg-out
The security event began on Sunday when a customer sent 4,000 Liquid Bitcoin, or L-BTC, to SideSwap’s peg-out service.
SideSwap allows users to move value from the Liquid sidechain back to the Bitcoin base layer through an authorized withdrawal process. In Liquid’s design, users can lock BTC and receive L-BTC on the sidechain at a one-to-one ratio. The sidechain is intended to support faster settlement and asset transfers without requiring every transaction to occur directly on Bitcoin’s base layer.
The 4,000 BTC withdrawal was therefore not a typical transfer inside Liquid. It involved the mechanism that connects Liquid-issued L-BTC back to native Bitcoin.
According to earlier reporting referenced in the source, the amount represented about 95% of the Bitcoin reportedly held in Liquid’s federation wallet at the time.
That scale immediately raised concerns about the bridge’s security and the backing available for L-BTC.
The actors demanded a fix before returning funds
The people responsible for the withdrawal communicated directly through messages embedded in Bitcoin transactions.
This allowed the actors and Blockstream to exchange instructions publicly without using a private messaging platform.
In one of those messages, the group told Blockstream that the flaw needed to be repaired before any funds would be returned.
“Please fix the bug first,” they wrote. They also warned that the chain remained at risk under the latest commit and asked Blockstream to make sure every node was patched.
The actors said they would transfer the money back after confirming that the fix had been completed.
This sequence created an unusual dependency: repayment was contingent on the actors accepting Blockstream’s statement that the vulnerable infrastructure had been secured.
Blockstream confirmed the nodes had been patched
Blockstream subsequently told the group, also through a signed transaction message, that its bridge nodes had been patched.
The company said the Bitcoin was “safe to return.”
Following that confirmation, the actors sent 3,400 BTC back to the Liquid Federation address.
On-chain data showed that the repayment was confirmed in Bitcoin block 965,950.
The transaction recovered roughly 85% of the original 4,000 BTC withdrawal.
The result substantially reduced the immediate financial exposure associated with the exploit, but it did not establish that the incident was fully resolved.
Nearly 598.5 BTC remain outside Liquid’s control
After the 3,400 BTC repayment, about 598.5 BTC remained in the withdrawal-linked address.
At the reported valuation, that amount was worth approximately $47 million.
The actors have not publicly explained why they retained those coins.
They have also not said whether another repayment will follow.
That uncertainty is central to the remaining risk around the incident.
The return of most of the funds changes the scale of the loss, but Liquid has not announced a resolution for the outstanding Bitcoin.
It has also not said whether the remaining amount will be treated as a loss, an unresolved claim, a potential bounty or something else.
The “white-hat” description remains disputed
The actors called themselves whitehats in a message attached to a Bitcoin transaction.
White-hat hackers are generally understood to identify and report security vulnerabilities so that developers can fix them, often within an agreed bug-bounty framework.
However, no public agreement has been disclosed showing that the Liquid actors had authorization to withdraw 4,000 BTC.
There are also no published terms showing that they were allowed to keep nearly 600 BTC.
That distinction matters because a self-description does not establish the legal or contractual status of an exploit.
The source makes clear that Blockstream has not publicly said the remaining 598.5 BTC represents an approved bounty.
Ledger’s CTO questioned the white-hat framing
Ledger Chief Technology Officer Charles Guillemet publicly challenged the actors’ characterization after the 3,400 BTC repayment.
He noted that the group still controlled around 600 BTC and argued that if the retained funds were supposed to represent a negotiated reward under an encrypted on-chain agreement, the arrangement looked more like extortion than conventional white-hat hacking.
His criticism focused on the absence of disclosed terms.
Traditional bug bounty programs generally establish compensation and return conditions before a researcher retains part of affected funds.
No comparable public arrangement has been disclosed between Blockstream and the Liquid actors.
The comment does not establish legal wrongdoing, but it highlights the ambiguity around the retained Bitcoin.
No legal status has been established
White-hat claims alone do not determine whether an actor acted lawfully.
A legal assessment would depend on several factors, including whether the withdrawal was authorized, how the funds were obtained, what communications occurred between the parties and what laws apply.
No U.S. regulator or law-enforcement agency has announced an action tied to the Liquid withdrawal.
The source therefore does not support describing the actors as criminals or as formally recognized security researchers.
The only confirmed facts are that they withdrew the Bitcoin, identified themselves as whitehats, demanded that the flaw be fixed, returned 3,400 BTC and still control about 598.5 BTC.
Liquid shut down bridge nodes after detecting the withdrawal
Liquid responded to the incident by disabling its bridge nodes.
It also asked exchanges to suspend L-BTC deposits and withdrawals while developers investigated the security problem and applied a patch.
That shutdown restricted movement between the Liquid sidechain and Bitcoin’s base layer.
Users could not rely on the normal peg process while the bridge remained suspended.
The decision was intended to prevent further movement through potentially vulnerable infrastructure.
However, Liquid has not yet announced when normal operations will resume.
The exact technical flaw remains undisclosed
Despite the repayment and patch, the underlying cause of the withdrawal is still unclear.
Blockstream has said that the key used during the withdrawal was not compromised, according to Reuters.
That statement rules out one possible explanation, but it does not identify the actual vulnerability.
The company has not released a full technical post-mortem explaining whether the issue affected SideSwap, Liquid’s bridge software, the Elements codebase or another component involved in the peg-out process.
Without that report, outside researchers cannot independently determine exactly how the 4,000 BTC withdrawal became possible.
The incident therefore remains only partially understood.
The repayment does not automatically resolve L-BTC backing questions
Liquid operates by allowing BTC to be locked and corresponding L-BTC to circulate on the sidechain.
That model depends on confidence that the Bitcoin backing the sidechain representation remains available for redemption.
The return of 3,400 BTC improves the position substantially.
However, Liquid has not disclosed whether the returned funds fully restore backing for the outstanding L-BTC supply.
It has also not explained how it plans to address any gap associated with the 598.5 BTC that remain under the actors’ control.
That is one of the most important unresolved operational questions.
Native Bitcoin was separate from the Liquid incident
For users holding BTC directly on the Bitcoin blockchain, the Liquid exploit did not represent a compromise of Bitcoin itself.
The affected system was Liquid’s sidechain and its bridge infrastructure.
Native BTC held directly on Bitcoin remains separate from the L-BTC peg system.
This distinction matters because bridge failures can interrupt the ability to move between networks even while the base blockchain continues functioning normally.
The incident illustrates how additional layers introduce their own custody, validation and message-processing risks.
The case differs from a conventional blockchain failure
A bridge system can fail even when both underlying chains continue to process transactions correctly.
The security risk sits in the mechanism that locks assets on one network and releases or represents them elsewhere.
If custody, validation or message processing fails, users can lose the ability to redeem assets even though the blockchain itself remains operational.
That distinction is important in Liquid’s case because the available reporting points to a bridge or peg-out problem rather than a failure of Bitcoin consensus.
The source does not identify a Bitcoin protocol vulnerability.
A similar dispute appeared in the Verus bridge case
The source compares the Liquid situation with the Verus Ethereum bridge exploit in May.
In that incident, the attacker returned 75% of the stolen assets and kept 1,350 ETH, worth about $2.8 million at the time.
The key difference is that Verus publicly offered settlement terms.
That gave the retained amount an explicit framework.
Liquid has not publicly disclosed an equivalent agreement.
As a result, the nearly 600 BTC still held by the actors cannot be described as an approved bounty based on the available information.
Communication through Bitcoin transactions became part of the recovery
One of the most unusual aspects of the incident is the use of Bitcoin itself as a communication channel.
The actors and Blockstream exchanged instructions through messages attached to transactions.
This allowed both sides to document demands and confirmations on-chain.
The mechanism did not require an outside messaging service.
More importantly, it created a visible sequence showing that the actors asked for the vulnerability to be fixed before returning the majority of the funds.
The repayment followed after Blockstream stated that the bridge nodes had been patched.
The bridge remains suspended despite the recovery
Liquid has not announced a reopening time for its bridge nodes.
Exchanges were still being asked to keep L-BTC deposits and withdrawals suspended.
That means the operational disruption continues even though most of the Bitcoin has been returned.
The continued suspension suggests that developers are not treating the repayment itself as sufficient to restart normal service.
They still need confidence that the patched infrastructure is safe.
The absence of a technical post-mortem also means users do not yet know what changed or how the vulnerability was addressed.
The remaining Bitcoin keeps the incident open
The 3,400 BTC repayment is a major recovery, but the case remains unresolved on several fronts.
Nearly $47 million in BTC is still controlled by the actors.
No public agreement explains whether they are allowed to retain it.
No reopening date has been announced.
No full technical report has been released.
And Liquid has not confirmed whether L-BTC backing has been fully restored.
Those issues prevent the incident from being treated as closed.
Conclusion
Liquid Network recovered 3,400 BTC after a 4,000 BTC withdrawal through its bridge system, restoring approximately 85% of the funds linked to the incident.
The repayment came after Blockstream confirmed through an on-chain message that its bridge nodes had been patched.
The actors, who called themselves whitehats, still control approximately 598.5 BTC worth about $47 million.
No public agreement establishes that the retained Bitcoin is an approved bounty, and the legal status of the actors has not been determined.
Final Takeaway
The return of 3,400 BTC dramatically reduces Liquid’s immediate exposure, but it does not resolve the most important operational and technical questions. The bridge remains suspended, the flaw has not been publicly explained, and nearly 600 BTC remain outside the federation’s control. Until Blockstream publishes a technical account, clarifies L-BTC backing and announces whether the remaining funds will be returned, the exploit should be viewed as partially recovered rather than fully resolved.




