About 598.5 BTC remain with the exploit author after on-chain negotiations and the fix announced by Blockstream.
Updated on September 7, 2026, with confirmation of the return.
3,400 BTC have been returned to the federation wallet of Liquid Network, following the withdrawal of around 4,000 bitcoin on September 6. The transfer, reported by Rob Hamilton at 15:46 UTC on September 7, was confirmed in block 965950 at 16:09 UTC.
The return transaction leaves 598.49955894 BTC at the sender’s address. This is the amount retained, about 598.5 BTC as a “fee”: the fee actually paid to miners was 1,768 satoshis. The public plaintext messages do not specify the terms of any agreed compensation.
The bug and network suspension
According to SideSwap’s reconstruction, on September 6 at 14:05 UTC a customer had sent 4,000 L-BTC to its peg-out service. The tokens were burned on Liquid and, at 14:28 UTC, 3,996 BTC were credited to the customer’s Bitcoin address. SideSwap said Blockstream had traced the L-BTC’s origin to an Elements bug, in the software on which Liquid is based. The platform ruled out compromises to its systems and to the peg-out authorization key.
The federation then disabled the bridge nodes, stopping the submission of new transactions. Exchanges were asked to suspend L-BTC deposits and withdrawals; SideSwap suspended swaps, peg-ins and peg-outs. According to Liquid, other assets issued on the network, including USDT, DePix and tokenized assets, were not involved in the exploit.
Messages before the return
The dialogue took place through OP_RETURN, the field that allows data to be included in Bitcoin transactions. On September 6, the authors described themselves as “white hats”, asking to be contacted on the blockchain. Blockstream responded by providing its security email address, then sent an encrypted message.
During the night of September 7, the authors proposed returning most of the funds to the federation wallet. In a subsequent message, they asked Blockstream to fix the bug and update every node before the transfer, attaching vulnerability details encrypted with Blockstream’s public key. The company replied with a signed message of thanks.
During the morning, Blockstream said the bridge nodes had been updated and that it was safe to return the funds. The message’s PGP signature can be verified with the company’s public key. At 12:43 UTC, a further request from the authors to verify the destination address was confirmed, along with additional encrypted details on the fix. Further encrypted messages between the parties followed before the return.
During the exchange, an unsigned PGP message also appeared, proposing an alternative address and suggesting that 98 BTC be retained. The 3,400 BTC transfer was instead sent to the federation wallet indicated in the previous communications.





