Why Is The Liquid Attacker Offering To Return The Bitcoin?
The party that withdrew roughly 4,000 BTC from Liquid Network’s federation wallet has said it will return most of the funds after Blockstream confirmed that the software vulnerability behind the incident had been fixed.
The attacker, who has described the operation as a white-hat action, communicated with Blockstream through Bitcoin OP_RETURN messages and PGP-encrypted text following the withdrawal.
In a message recorded at Bitcoin block 965,875, the party instructed Blockstream to “fix the bug first” and make sure every affected node had been patched before the funds were returned.
Blockstream later responded through a PGP-signed onchain message stating, “Bridge nodes are patched, safe to return the funds.” The signature matched the security key published by Blockstream.
The roughly 4,000 BTC nevertheless remained in the attacker-controlled wallet at the time of publication, meaning the promised return had not yet been completed.
The latest exchange followed an earlier message in which the attacker offered to send most of the bitcoin back to the federation address. Blockstream had initially contacted the party through an onchain transaction at block 965,822 and asked it to communicate with the company’s security team.
How Did Nearly 4,000 BTC Leave The Federation Wallet?
Liquid disclosed on Sept. 6 that roughly 4,000 BTC, worth about $320 million at the time, had been withdrawn from the federation wallet backing its L-BTC token.
The transaction initially raised questions about whether SideSwap’s Peg-out Authorization Key or Liquid’s federation infrastructure had been compromised. Subsequent disclosures point instead to a software flaw that allowed invalid L-BTC to be created before it was redeemed through the normal peg-out process.
SideSwap said the transaction involved 4,000 L-BTC being sent to its peg-out service. The service processed the request using a valid authorization and burned the tokens, after which the Liquid Federation released approximately 3,996 BTC to the customer’s Bitcoin address.
Blockstream later determined that the L-BTC had been created through a bug in Elements, the software framework underlying Liquid, according to SideSwap.
SideSwap said neither its platform nor its peg-out authorization key had been compromised. That distinction matters because the peg-out system appears to have processed technically valid tokens even though those tokens had been improperly created through the underlying software vulnerability.
Investor Takeaway
The potential return of the bitcoin would sharply reduce the direct financial damage, but it does not remove the security issue. Investors should focus on how invalid L-BTC was created, whether every federation node is patched, and when exchanges are comfortable reopening deposits and withdrawals.
Why Is Liquid Still Paused?
The Liquid Federation has paused network activity while the incident is investigated and infrastructure is patched. Bridge nodes were disabled, and exchanges were urged to suspend L-BTC deposits and withdrawals.
SideSwap said swaps, peg-ins and peg-outs also remain paused until the Liquid network resumes normal operation.
The suspension is intended to prevent further exploitation while federation members verify that the affected software has been updated across the network. The attacker’s own messages made a complete patch a condition for returning the bitcoin, suggesting that the party was concerned about the vulnerability remaining exploitable on unpatched nodes.
Even with Blockstream stating that bridge nodes are now patched, operators will need to determine whether the vulnerability could have affected other balances or transactions before fully restoring service.
For exchanges and trading firms using Liquid to move bitcoin and L-BTC, the immediate operational issue is when deposits, withdrawals and conversions can safely restart.
What Happens If The Bitcoin Is Returned?
A successful return would transform the incident from a roughly $320 million asset loss into primarily a software-security and infrastructure failure, although the episode would still rank among the most serious incidents involving a major Bitcoin sidechain.
The final outcome will depend on how much of the 4,000 BTC is returned and what terms, if any, are attached. The attacker has offered to return most rather than explicitly all of the funds.
The larger issue for Liquid is confidence in its federation and peg mechanisms. L-BTC is designed to represent bitcoin held by the federation, so the ability to create tokens through a software bug and redeem them for real BTC strikes directly at the integrity of that backing process.
Attention will therefore turn to a full technical explanation of the Elements vulnerability, the versions affected, how the attacker discovered it and whether additional safeguards will be introduced around token issuance and peg-outs.
Until the funds are returned and the network is fully restored, the incident remains unresolved. The attacker has accepted Blockstream’s demand for communication and Blockstream has declared the bridge nodes patched, but the decisive step will be the movement of the bitcoin back to federation control.
