Morning Edition · Wednesday, September 9, 2026Published at 1:46 AM EDT · New York
The group that drained the federation wallet backing L-BTC left about $47 million in bitcoin outstanding as a self-declared bounty, and researchers dispute its claim to be acting in good faith.

A group that drained roughly 4,000 bitcoin from the federation wallet backing Blockstream's Liquid sidechain has returned 3,400 of those coins after negotiations conducted through on-chain messages and encrypted channels. About 598.5 bitcoin, near $47 million at current prices, remains with the attackers. Blockstream said it patched the affected bridge nodes before the return took place.
Liquid is a Bitcoin sidechain whose L-BTC token is backed one-for-one by bitcoin held in a wallet controlled by a federation of exchanges and companies. Reporting on the incident attributes the entry point to a defect in the network's range proofs, the cryptographic proofs that confirm a hidden transaction amount falls inside a valid range without revealing it. Liquid uses confidential transactions, so amounts are not published, and a soundness defect in that verification process lets an attacker assert value that does not exist rather than steal a key. CoinDesk put the initial drain at about $320 million when the coins moved on Sunday.
The parties disagree about what happened next. The attackers described themselves as white hats, meaning security researchers acting to protect a system rather than to profit from it, and framed the retained coins as a bounty. Security practitioners including Ledger's chief technology officer rejected that description, noting that the funds moved first and the offer to talk followed. Blockstream has not published a full post-mortem or named the individuals involved. Both readings fit the on-chain record, and what separates them is evidence that has not been made public: whether the group attempted disclosure before moving funds.
The scale matters against the size of the Bitcoin-native application layer. DeFiLlama puts total value locked across Bitcoin-based protocols at $4.25 billion, so a single federation wallet held bitcoin worth close to eight percent of that figure. The failure was not a smart-contract bug in the ordinary sense. It existed within the proof system that lets a chain hide amounts while still enforcing conservation of supply, a component that validator re-execution cannot independently check.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Blockstream and the federation members recover about 85 percent of the peg's backing without litigation or an insolvency event, exchanges holding L-BTC avoid marking the peg down, and the attackers convert an unauthorized transfer of roughly $320 million into a negotiated $47 million retention plus a reputational defense.
The mechanics are documented and the intent is not: CertiK and Bitquery trace the entry point to an ambiguous cache-key encoding in the rangeproof verification cache in the Elements codebase rather than to a defect in range proofs themselves, and no party has published evidence that the group attempted disclosure before moving the coins.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Federated sidechains concentrate custody in one wallet and then rely on cryptography, not on redundant validation, to keep the peg's backing accurate. Holders of L-BTC and the exchanges that run federation nodes carry the loss when that cryptography fails, and the recovery depended entirely on the attackers' willingness to send coins back. For Blockstream and for the wider set of confidential-transaction designs, the practical consequence is that proof soundness must now be treated as seriously as key management in custody decisions, which raises the cost of running any bridge that hides amounts.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · CoinDesk · Rekt News
Comments
0No comments yet.