
Liquid Network Attacker Returns 3,400 BTC After Bug Fix
Key Takeaways
- The hacker returned 3,400 BTC, or about 85% of the nearly 4,000 BTC withdrawn from a Liquid Federation wallet over the weekend.
- Blockstream said it patched its bridge nodes before the funds were sent back.
- At the time, roughly 598.5 BTC, worth about $47 million, remained in the attacker’s wallet.
The hacker who withdrew nearly 4,000 BTC from Liquid Network over the weekend has returned 3,400 BTC after Blockstream said it patched its bridge nodes.
The returned Bitcoin represents about 85% of the funds withdrawn from Liquid’s federation wallet. Still, around 598.5 BTC, worth roughly $47.3 million, remained in the attacker’s wallet.
The incident occurred on September 6, when roughly 4,000 BTC, then valued at about $320 million, was withdrawn from the federation wallet backing Liquid Bitcoin, or L-BTC. Initially, Liquid described those responsible as “purported white-hat hackers.”
The hacker communicated with Blockstream through Bitcoin OP_RETURN messages and PGP-encrypted text. In a message at block 965,875, the hacker demanded that Blockstream “fix the bug first” and ensure every node was patched before returning the Bitcoin.
Blockstream then sent a PGP-signed on-chain message stating that its bridge nodes had been patched and that the funds could be returned safely. The hacker then returned 3,400 BTC to the federation address in block 965,950, leaving about 598.5 BTC ($47.3 million) in the hacker’s wallet.
Both parties began communicating after Liquid publicly confirmed the exploit. According to the network, the funds were withdrawn through the SideSwap Peg-out Authorization Key, although the key itself was not compromised.
In a statement on X, SideSwap said that the original transaction involved 4,000 L-BTC sent through its peg-out service. The service burned the tokens through a valid authorization before the Liquid Federation released roughly 3,996 BTC to the customer’s Bitcoin address.
Statement on today’s Liquid incident Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out authorisation, and at 14:28 UTC the Liquid Federation paid 3,996 BTC to the customer’s Bitcoin address.
— SideSwap (@side_swap) Sep 6, 2026
Blockstream later determined that the L-BTC had been created through a bug in the underlying Elements software. According to SideSwap, neither its systems nor its peg-out authorization key had been compromised.
Liquid had paused its network activity and asked exchanges to suspend L-BTC deposits and withdrawals. SideSwap said that swaps, peg-ins, and peg-outs would remain paused until the network resumes.
The return of 3,400 BTC substantially reduced the remaining outstanding amount. However, roughly 598.5 BTC remains with the attacker, while questions remain over the technical flaw that enabled the exploit.
Get started on WEEX with a simple 40 USDT reward. Deposit 100 USDT, make your trade, and claim the bonus.
Disclaimer: All content on The Moon Show is for informational and educational purposes only. The opinions expressed do not constitute financial advice or recommendations to buy, sell, or trade cryptocurrencies. Trading involves significant risk and may result in substantial losses. Always seek independent financial advice before making investment decisions. The Moon Show is not responsible for any financial losses or decisions made based on the information provided.
Please view the full disclaimer at: https://themoonshow.com/disclaimer


