# Liquid Network Recovers 3,400 of 4,000 Bitcoin After Attackers Forced a Patch First

The drain used a defect in the Elements software that let invalid L-BTC pass through the federation's normal peg-out, not a compromise of federation keys, and about 598 bitcoin remain with the attackers.

- Published: 2026-09-08T05:45:27.037Z
- Canonical: https://polylog.news/crypto/2026-09-08/liquid-network-recovers-3-400-of-4-000-bitcoin-after-attacke
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network), [Bitcoin Magazine](https://bitcoinmagazine.com/news/liquid-gets-3400-btc-back-after-on-chain-talks-white-hats-keep-598-5-btc), [Bitcoin Magazine](https://bitcoinmagazine.com/news/alleged-white-hat-hackers-withdraw-4000-bitcoin-from-blockstreams-liquid-network-federation-reserves), [Polylog editors](https://polylog.news)

A party that describes itself as white-hat returned 3,400 bitcoin to the federation wallet of Blockstream's Liquid Network on Monday, after taking about 4,000 bitcoin from the reserves that back the sidechain's L-BTC token. [CoinDesk reported](https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network) that close to 47 million dollars in bitcoin is still outstanding and that talks over the remainder continue. [Bitcoin Magazine put the retained amount at 598.5 bitcoin](https://bitcoinmagazine.com/news/liquid-gets-3400-btc-back-after-on-chain-talks-white-hats-keep-598-5-btc), returned only after Blockstream said the bridge nodes had been patched.

The mechanism matters more than the amount. Liquid is a Bitcoin sidechain whose peg is operated by a federation of functionaries rather than by a single custodian. According to reporting on the incident, a flaw in the Elements software that runs the sidechain allowed the creation of invalid L-BTC, which was then redeemed for real bitcoin through the ordinary peg-out path. The federation's signing keys were not stolen. The authorization layer did exactly what it was built to do, and it did so on the strength of an accounting entry that should never have existed.

The negotiation was itself conducted on-chain. The attackers said they would return the funds once every affected node was patched, and Blockstream answered with a signed message stating that the bridge nodes were fixed and the funds were safe to return, according to [Cointelegraph's account of the exchange](https://t.me/cointelegraph/71994). Liquid had [disabled bridge nodes and paused the peg](https://bitcoinmagazine.com/news/alleged-white-hat-hackers-withdraw-4000-bitcoin-from-blockstreams-liquid-network-federation-reserves) after the withdrawals were detected.

Two readings of the retained 598.5 bitcoin are circulating. The attackers present it as a bounty proportionate to the severity of the bug they surfaced. Liquid users can point out that no published bounty program authorized a self-assessed fee taken from reserves that back a circulating token. Neither side has disclosed an agreement, and no attribution to a named actor has been made public.

## What this means

Every wrapped-bitcoin design converts bitcoin's settlement guarantee into a claim on a software accounting layer and the people who operate it. Here the operators were honest and the ledger logic was not, so the loss occurred through the network's normal, authorized withdrawal process. Holders of bridged bitcoin representations, and the exchanges that use Liquid for fast settlement, carry that code risk directly, while native bitcoin holders do not. The recovery came from a voluntary return, which means the practical backstop was the attackers' choice rather than any enforceable control.

## What to watch

- Whether the remaining 598.5 bitcoin is returned, kept under a disclosed agreement, or becomes a law-enforcement matter, which would set the precedent for how self-declared white hats price their own bounties.
- Blockstream's post-incident disclosure of the Elements defect and the audit scope around it, since other Elements-derived chains inherit the same code.
- Whether exchanges that rely on Liquid for inter-venue settlement restore full peg-in and peg-out flows or reduce their balances there.
