# Blockstream Demands the 598 Bitcoin Liquid Attackers Kept as a Self-Declared Finder's Fee

The group returned 3,400 of about 4,000 bitcoin taken from the sidechain's federation wallet, keeping exactly 15 percent and worth roughly $47 million.

- Published: 2026-09-13T05:57:01.509Z
- Canonical: https://polylog.news/crypto/2026-09-13/blockstream-demands-the-598-bitcoin-liquid-attackers-kept-as
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Bitcoin Magazine](https://bitcoinmagazine.com/news/blockstream-tells-demands-bitcoin), [CoinDesk](https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network), [SecurityWeek](https://www.securityweek.com/hackers-return-263-million-stolen-from-liquid-network/)

Blockstream is [publicly demanding the return of the bitcoin still held](https://bitcoinmagazine.com/news/blockstream-tells-demands-bitcoin) by the group that drained the Liquid Network last weekend. Attackers removed roughly 4,000 bitcoin, about $320 million at the time, from the federation wallet of the Bitcoin sidechain that Blockstream develops. The company disabled nodes and suspended transactions once it detected the withdrawal.

The group [returned 3,400 bitcoin](https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network) the following day, worth about $263 million, and [kept 598.5 bitcoin](https://www.securityweek.com/hackers-return-263-million-stolen-from-liquid-network/), which it describes as a finder's fee. The retained amount is exactly 15 percent of what was taken, worth roughly $47 million at a bitcoin price near $78,500. The two sides first made contact through the OP_RETURN data field of a Bitcoin transaction sent from the address holding the funds, then moved to encrypted messages signed with keys that can be checked against Blockstream's published security key.

Blockstream attributed the incident to a software bug in Elements, the codebase Liquid is built on, rather than to compromised keys. The affected funds moved through SideSwap, an approved trading platform on the network, and SideSwap also pointed to the Elements bug as the root cause. No party has published a full technical postmortem of the defect.

Liquid is a federated sidechain. Bitcoin locked into it is held by a set of functionaries running a shared multisignature arrangement, and users hold a claim on that federation rather than on the Bitcoin base chain. That structure means a consensus-software bug and a custody failure are not separate categories here, because the same code governs who can move the pooled coins. The unresolved question is not whether the money can be recovered but whether an uninvited party gets to set its own fee for finding the hole.

## What this means

An attacker keeping a fixed percentage and negotiating the rest back has become a repeatable playbook, and it prices security failures for protocols on terms the protocol does not set. Liquid users and the exchanges that route bitcoin through it are the exposed parties, because their claim depends on federation software rather than on the Bitcoin base layer. If Blockstream recovers the remaining coins without paying, protocols gain leverage to refuse these fees. If the group keeps the $47 million with no consequence, every future attacker has a demonstrated market rate.

## What to watch

- Whether Blockstream publishes a technical postmortem naming the Elements defect, which determines how many other Elements-based chains have to patch.
- Whether the remaining 598.5 bitcoin move, and to where, since a move to a mixer would end the white-hat framing.
- Whether exchanges reduce the bitcoin they hold on Liquid, which would show institutional users repricing federated sidechain custody.
