Morning Edition · Sunday, September 13, 2026Published at 1:57 AM EDT · New York
The group returned 3,400 of about 4,000 bitcoin taken from the sidechain's federation wallet, keeping exactly 15 percent and worth roughly $47 million.

Blockstream is publicly demanding the return of the bitcoin still held by the group that drained the Liquid Network last weekend. Attackers removed roughly 4,000 bitcoin, about $320 million at the time, from the federation wallet of the Bitcoin sidechain that Blockstream develops. The company disabled nodes and suspended transactions once it detected the withdrawal.
The group returned 3,400 bitcoin the following day, worth about $263 million, and kept 598.5 bitcoin, which it describes as a finder's fee. The retained amount is exactly 15 percent of what was taken, worth roughly $47 million at a bitcoin price near $78,500. The two sides first made contact through the OP_RETURN data field of a Bitcoin transaction sent from the address holding the funds, then moved to encrypted messages signed with keys that can be checked against Blockstream's published security key.
Blockstream attributed the incident to a software bug in Elements, the codebase Liquid is built on, rather than to compromised keys. The affected funds moved through SideSwap, an approved trading platform on the network, and SideSwap also pointed to the Elements bug as the root cause. No party has published a full technical postmortem of the defect.
Liquid is a federated sidechain. Bitcoin locked into it is held by a set of functionaries running a shared multisignature arrangement, and users hold a claim on that federation rather than on the Bitcoin base chain. That structure means a consensus-software bug and a custody failure are not separate categories here, because the same code governs who can move the pooled coins. The unresolved question is not whether the money can be recovered but whether an uninvited party gets to set its own fee for finding the hole.
Blockstream gains by refusing to treat the retained coins as a bounty, because and that label sets the price for every future negotiation, while the group gains from a framing that may complicate prosecution.
Part of a tracked trend
Negotiated Attacker Fees Become Standard Practice
Large on-chain thefts increasingly end in a negotiated partial return where the attacker unilaterally sets a percentage bounty, turning exploits into a de facto pricing mechanism for unfound bugs and weakening the deterrent value of formal bug bounty programs.
Start a discussion in Townsquare.
More from this edition
Independent reporting traces the root cause to a range-proof verification cache defect in Elements and confirms SideSwap's peg-out key was not compromised, but no party has published a postmortem, and whether the group ever intended a bounty or only proposed one after Blockstream paused the network remains unestablished.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
An attacker keeping a fixed percentage and negotiating the rest back has become a repeatable playbook, and it prices security failures for protocols on terms the protocol does not set. Liquid users and the exchanges that route bitcoin through it are the exposed parties, because their claim depends on federation software rather than on the Bitcoin base layer. If Blockstream recovers the remaining coins without paying, protocols gain leverage to refuse these fees. If the group keeps the $47 million with no consequence, every future attacker has a demonstrated market rate.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · CoinDesk · SecurityWeek
Comments
0No comments yet.