Morning Edition · Tuesday, September 8, 2026Published at 1:45 AM EDT · New York
The drain used a defect in the Elements software that let invalid L-BTC pass through the federation's normal peg-out, not a compromise of federation keys, and about 598 bitcoin remain with the attackers.

A party that describes itself as white-hat returned 3,400 bitcoin to the federation wallet of Blockstream's Liquid Network on Monday, after taking about 4,000 bitcoin from the reserves that back the sidechain's L-BTC token. CoinDesk reported that close to 47 million dollars in bitcoin is still outstanding and that talks over the remainder continue. Bitcoin Magazine put the retained amount at 598.5 bitcoin, returned only after Blockstream said the bridge nodes had been patched.
The mechanism matters more than the amount. Liquid is a Bitcoin sidechain whose peg is operated by a federation of functionaries rather than by a single custodian. According to reporting on the incident, a flaw in the Elements software that runs the sidechain allowed the creation of invalid L-BTC, which was then redeemed for real bitcoin through the ordinary peg-out path. The federation's signing keys were not stolen. The authorization layer did exactly what it was built to do, and it did so on the strength of an accounting entry that should never have existed.
The negotiation was itself conducted on-chain. The attackers said they would return the funds once every affected node was patched, and Blockstream answered with a signed message stating that the bridge nodes were fixed and the funds were safe to return, according to Cointelegraph's account of the exchange. Liquid had disabled bridge nodes and paused the peg after the withdrawals were detected.
Two readings of the retained 598.5 bitcoin are circulating. The attackers present it as a bounty proportionate to the severity of the bug they surfaced. Liquid users can point out that no published bounty program authorized a self-assessed fee taken from reserves that back a circulating token. Neither side has disclosed an agreement, and no attribution to a named actor has been made public.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
The attackers convert a theft into a self-priced 47 million dollar fee by adopting the white-hat label, and Blockstream gains a recovery narrative that limits the damage to Liquid's standing with the exchanges that settle through it.
The amounts and the range-proof verification defect in Elements are corroborated across outlets, but no bounty agreement has been published, Blockstream calls the actor only a purported white hat and Ledger's chief technology officer rejects the label, and roughly 4,000 of about 4,200 reserve bitcoin left while the peg stays paused.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Every wrapped-bitcoin design converts bitcoin's settlement guarantee into a claim on a software accounting layer and the people who operate it. Here the operators were honest and the ledger logic was not, so the loss occurred through the network's normal, authorized withdrawal process. Holders of bridged bitcoin representations, and the exchanges that use Liquid for fast settlement, carry that code risk directly, while native bitcoin holders do not. The recovery came from a voluntary return, which means the practical backstop was the attackers' choice rather than any enforceable control.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Bitcoin Magazine · Bitcoin Magazine · Polylog editors
Comments
0No comments yet.