Article is online

Approximately $47 Million Still Unrecovered After Liquid Network Exploit as Blockstream Negotiates With 'White Hats'

Approximately $47 Million Still Unrecovered After Liquid Network Exploit as Blockstream Negotiates With 'White Hats'

Table of Contents




You might want to know


Who is negotiating with Blockstream to recover the remaining funds, and what are the likely terms?


How did the software flaw allow unbacked L-BTC to be exchanged for reserve Bitcoin?



Main Topic


Blockstream, the company behind the Liquid sidechain, is in active discussions to recover roughly 598.5 BTC still outstanding after a recent exploit of the Liquid Network. The incident began when a vulnerability in Elements-based software permitted the creation of unbacked L-BTC tokens. Those tokens were then exchanged for reserve Bitcoin, enabling a withdrawal of nearly 4,000 BTC in total.



The attackers returned about 3,400 BTC on Monday, leaving approximately 600 BTC — valued near $47 million — unrecovered. Liquid Network published an incident update indicating that talks between Blockstream and the individuals responsible are ongoing, with the stated objective of securing the return of the remaining coins. Liquid has not disclosed the specifics of those negotiations or provided a timetable for complete recovery.



According to the network’s developers, the exploit involved a validation failure at the transaction level. After creating unbacked L-BTC, the unknown individuals routed the funds through SideSwap, a member of the Liquid Federation that operates a withdrawal service. Because the transaction-level checks accepted the unbacked tokens as valid before the peg-out began, both SideSwap’s node and Liquid’s globally distributed functionary nodes accepted the tokens and allowed the reserve Bitcoin to be released.



As a result of the withdrawals and other transactions that occurred before operations were paused, Liquid’s reserve dropped sharply from roughly 4,205 BTC to about 197 BTC. Liquid also stated that USDT and other assets issued on the Liquid Network were not affected by the vulnerability, though users were unable to transact while the network remained paused.



The Liquid Federation emphasized that its functionary nodes were not compromised and that no private keys were stolen, noting that the peg-out mechanism that authorizes withdrawals to whitelisted addresses continued to operate as designed. Nonetheless, the unusual validation failure allowed the exploit to proceed until network operations were halted and mitigations were put in place.



At the time of the incident, the actors posted a message on Bitcoin’s blockchain claiming to be white-hat security researchers. They subsequently returned the majority of the stolen BTC, prompting debate within the community. Some observers, including Ledger’s Chief Technology Officer Charles Guillemet, cast doubt on the white-hat claim. Guillemet noted that because the actors still hold roughly 600 BTC, and if that remainder were part of a negotiated reward under an on-chain encrypted agreement, it would resemble extortion rather than responsible disclosure.



In response to the exploit, Liquid’s developers implemented a patch to bridge nodes and said Blockstream is preparing an emergency software update that will be reviewed before deployment. Once finalized, network operators will apply further corrections to restore normal operations and adjust the network state to reject the invalid peg-outs that allowed the exploit.



Liquid stated that its immediate priorities are recovering the remaining funds and safely resuming normal network operations as quickly as possible. The company has provided regular updates through its incident report and continues to coordinate remediation steps with federation members and Blockstream.



Key Insights Table



















Aspect Description
Key Fact 1 A flaw in Elements software allowed the creation of unbacked L-BTC which were exchanged for reserve Bitcoin.
Key Fact 2 Attackers returned ~3,400 BTC, leaving ~598.5 BTC (about $47M) still outstanding as negotiations continue.


Afterwards...


Looking forward, restoring confidence in sidechain and bridge security will likely require improved transaction-level validation, third-party audits, and faster coordinated incident response across federated operators. Continued focus on formal verification of critical bridge code, real-time monitoring for anomalous peg-outs, and stronger operational controls at federation members would help reduce the risk of similar events. Exploring automated rollback mechanisms and on-chain dispute-resolution protocols could also provide additional layers of protection while preserving the interoperability benefits sidechains deliver.



As Blockstream and Liquid work to finalize fixes and negotiate recovery, the broader ecosystem can learn from this event to strengthen best practices for federated networks, ensuring greater resilience and clearer incentives for responsible disclosure.


Last edited at:2026/9/8
#BTC#USDT

數字匠人

Idle Passerby