# Attackers Return 3,400 of 4,000 Bitcoin Taken From Blockstream's Liquid Sidechain and Keep 598.5

The group that drained the federation wallet backing L-BTC left about $47 million in bitcoin outstanding as a self-declared bounty, and researchers dispute its claim to be acting in good faith.

- Published: 2026-09-09T05:46:55.977Z
- Canonical: https://polylog.news/crypto/2026-09-09/attackers-return-3-400-of-4-000-bitcoin-taken-from-blockstre
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Bitcoin Magazine](https://bitcoinmagazine.com/news/liquid-gets-3400-btc-back-after-on-chain-talks-white-hats-keep-598-5-btc), [CoinDesk](https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network), [Rekt News](https://www.rekt.news/)

A group that drained roughly 4,000 bitcoin from the federation wallet backing Blockstream's Liquid sidechain has [returned 3,400 of those coins](https://bitcoinmagazine.com/news/liquid-gets-3400-btc-back-after-on-chain-talks-white-hats-keep-598-5-btc) after negotiations conducted through on-chain messages and encrypted channels. About 598.5 bitcoin, near $47 million at current prices, remains with the attackers. Blockstream said it patched the affected bridge nodes before the return took place.

Liquid is a Bitcoin sidechain whose L-BTC token is backed one-for-one by bitcoin held in a wallet controlled by a federation of exchanges and companies. Reporting on the incident attributes the entry point to a defect in the network's range proofs, the cryptographic proofs that confirm a hidden transaction amount falls inside a valid range without revealing it. Liquid uses confidential transactions, so amounts are not published, and a soundness defect in that verification process lets an attacker assert value that does not exist rather than steal a key. [CoinDesk put the initial drain at about $320 million](https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys) when the coins moved on Sunday.

The parties disagree about what happened next. The attackers described themselves as white hats, meaning security researchers acting to protect a system rather than to profit from it, and framed the retained coins as a bounty. Security practitioners including Ledger's chief technology officer rejected that description, noting that the funds moved first and the offer to talk followed. Blockstream has not published a full post-mortem or named the individuals involved. Both readings fit the on-chain record, and what separates them is evidence that has not been made public: whether the group attempted disclosure before moving funds.

The scale matters against the size of the Bitcoin-native application layer. [DeFiLlama](https://defillama.com/) puts total value locked across Bitcoin-based protocols at $4.25 billion, so a single federation wallet held bitcoin worth close to eight percent of that figure. The failure was not a smart-contract bug in the ordinary sense. It existed within the proof system that lets a chain hide amounts while still enforcing conservation of supply, a component that validator re-execution cannot independently check.

## What this means

Federated sidechains concentrate custody in one wallet and then rely on cryptography, not on redundant validation, to keep the peg's backing accurate. Holders of L-BTC and the exchanges that run federation nodes carry the loss when that cryptography fails, and the recovery depended entirely on the attackers' willingness to send coins back. For Blockstream and for the wider set of confidential-transaction designs, the practical consequence is that proof soundness must now be treated as seriously as key management in custody decisions, which raises the cost of running any bridge that hides amounts.

## What to watch

- Whether Blockstream publishes a technical post-mortem naming the exact defect and the patch, which would tell other confidential-transaction chains, including Monero-style designs, whether they share the flaw.
- Whether the remaining 598.5 bitcoin moves to an exchange or a mixing service, which would contradict the group's stated intent and shift the incident from negotiation to law enforcement.
- Whether exchanges that hold L-BTC reduce their exposure or keep issuing, which is the clearest measure of how much institutional trust the peg retains.
