A self-described white-hat attacker behind the $320 million Liquid Network security incident has returned 3,400 BTC after exploiting a vulnerability that allowed nearly 4,000 BTC to be withdrawn from the Bitcoin sidechain. The returned funds were worth roughly $270 million at prevailing prices, substantially reducing the potential losses from an incident that placed fresh scrutiny on the infrastructure supporting tokenized Bitcoin.
Approximately 598.5 BTC remains under the attacker’s control, however, leaving tens of millions of dollars still outstanding. The unusual partial return followed an exchange of messages between the attacker and Blockstream conducted through Bitcoin transactions, with the attacker indicating that most of the funds would be returned after the underlying vulnerability had been addressed.
Liquid Network initially reported that roughly 4,000 BTC, valued at approximately $320 million at the time, had been withdrawn from its federation wallet. The amount represented the vast majority of the Bitcoin reportedly held in the wallet before the incident, immediately making the exploit one of the most significant crypto security events of the year.
Blockstream patches vulnerability before Bitcoin return
The incident appears to have involved a vulnerability in Elements, the open-source software that underpins Liquid. Around 4,000 L-BTC was reportedly sent through SideSwap’s peg-out service and burned with valid authorization, resulting in a corresponding amount of BTC being released from the Liquid Federation.
SideSwap said its systems and Peg-out Authorization Key had not been compromised. Blockstream subsequently traced the incident to an Elements bug that allowed the L-BTC used in the transaction to be created improperly, shifting attention away from stolen cryptographic keys and toward a flaw in the software governing the system.
The attacker identified themselves as a white hat through messages embedded in Bitcoin transactions and indicated that the vulnerability should be fixed before the funds were returned. Blockstream later confirmed through an on-chain message that affected bridge nodes had been patched and that the Bitcoin could safely be sent back, after which the attacker transferred 3,400 BTC to the Liquid Federation.
The exchange created an unusual situation in which the Bitcoin blockchain itself effectively became a public communication channel between the two parties. More importantly for Liquid users, the return of most of the funds significantly reduced the immediate financial consequences of the exploit while allowing attention to shift toward the remaining Bitcoin and the circumstances that allowed the vulnerability to reach production.
Nearly 600 BTC remains outstanding
Despite the recovery, approximately 598.5 BTC remains under the attacker’s control. At Bitcoin prices around the time of the incident, that portion was worth roughly $47 million, making the unresolved balance substantial even after the majority of the withdrawn funds were returned.
The attacker’s decision to retain part of the Bitcoin has prompted speculation that the remaining funds could be treated as a bug bounty. There has been no confirmed public agreement establishing the retained Bitcoin as an authorized reward, however, leaving questions over whether the funds will ultimately be returned or become the subject of further negotiations.
The distinction is significant because conventional white-hat security research typically involves reporting vulnerabilities through established disclosure channels and negotiating compensation with the affected organization. Removing hundreds of millions of dollars before returning most of it represents a far more aggressive approach, regardless of how the attacker characterizes the operation.
The incident also highlights the distinction between the security of Bitcoin itself and the additional infrastructure built around it. Liquid is a Bitcoin sidechain designed to support faster and more confidential transactions, as well as assets including stablecoins and tokenized securities. Its L-BTC asset is designed to maintain a one-to-one relationship with Bitcoin controlled through the Liquid Federation.
While the majority of the withdrawn Bitcoin has now been recovered, the exploit demonstrates how vulnerabilities in software, bridges and federation infrastructure can create significant financial risks without compromising Bitcoin’s underlying network. For Liquid and Blockstream, attention will now focus on the full technical explanation of the vulnerability, the status of the remaining BTC and measures designed to prevent a similar incident from occurring again.
For the wider crypto industry, the episode is another reminder that tokenized and bridged versions of major digital assets inherit additional layers of technical risk. The security of those assets ultimately depends not only on their underlying blockchains, but also on every piece of infrastructure responsible for issuing, transferring and redeeming them.









