A high-stakes security incident involving Blockstream’s Liquid Network reached a major turning point when an entity claiming white-hat hacker status returned 3,400 Bitcoin (BTC) to the federation’s reserves. The returned funds follow an unauthorized withdrawal of nearly 4,000 BTC executed on Sunday. However, rather than returning the entirety of the assets, the individual or group retained approximately 598.5 BTC—representing roughly 15% of the total consolidated pile and valued at approximately $48 million to nearly $50 million at current market prices—as an unnegotiated, implied finder’s fee.

The return transfer, recorded under transaction hash bc49a46d, was formally confirmed on the Bitcoin blockchain at 16:09 UTC on September 7. Blockchain data confirms that exactly 3,400 BTC was routed back to the designated, labeled Liquid peg script address. Meanwhile, the remaining 598.5 BTC was directed back to the white-hat actor’s primary holder address as change. This dramatic partial recovery materialized after more than twenty-four hours of methodical, publicly visible communications conducted entirely through encoded messages embedded directly inside Bitcoin transactions.

The public dialogue between the white-hat hacker and the engineering teams maintaining Liquid began shortly after the initial exploit occurred. Operating from the address holding the nearly 4,000 BTC removed from the Liquid Network federation reserves, the individual broadcasted an initial transaction containing an arbitrary data field known as OP_RETURN. The embedded message, broadcast in transaction c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19, was brief and direct: “contact us on chain.”

In response to the initial broadcast, an address linked directly to Blockstream replied on-chain with a simple direction instructing the party to establish communication via email. As negotiations escalated beyond initial contact, subsequent broadcasts from the Blockstream-controlled address adopted enhanced cryptographic security protocols. Notes sent from the sender contained Electrum-encrypted payloads along with PGP signatures that could be independently validated and verified against Blockstream’s officially published security key.

The dialogue progressed significantly when transaction activity reached block 965869. The white-hat actor published a clear-text inquiry in transaction 3a3eac4a26395b8c2563aaf1eb8b1b77798c81c7d6337f51321827a244a480aa, asking whether returning “most” of the funds back to the federation script address would be considered acceptable by the network maintainers. In this transaction, a minor output of just 1,000 satoshis was utilized solely as a message carrier to transmit the clear-text text onto the public ledger.

Shortly after asking about the partial return, the white-hat actor posted another explicit instruction in transaction 83825b2135dd0abac12c9dfe17f29ab81b3427e1ae864947b0bebce5e47c3c4b, warning core developers about underlying technical vulnerabilities. The message urged the technical team to fix the underlying security flaw before any funds were transferred back to the network: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” Accompanying this clear-text message was an encrypted blurb of data targeted specifically to Blockstream’s public PGP key, ensuring that sensitive vulnerability details remained confidential.

Within the very same block, the Blockstream-linked address acknowledged the warning with a clear-signed reply stating, “Yes, thank you.” A multi-hour operational window ensued as engineers worked to address the flaw across the infrastructure. Eventually, the same Blockstream address published another clear-text update in transaction 87dc0a20099a94c2caaa3fa93d1724cfe41b05ae5e0778cc0e8994b22e81120c, confirming that the remediation effort was complete, stating: “Bridge nodes are patched, safe to return the funds.”

Minutes after receiving public confirmation that the bridge nodes had been successfully patched and secured, the white-hat actor executed transaction bc49a46d, returning 3,400 BTC—amounting to 85% of the taken assets—back to the federation’s script. The decision to hold back 15% immediately sparked intense debate across the cryptocurrency community, particularly on social media platforms such as X. While some industry observers viewed the outcome positively, characterizing the return of 85% as significantly better than losing the funds entirely, others expressed shock at the sheer monetary magnitude of the retained portion. Although a 15% finder’s fee is not uncommon in standard software bug bounty frameworks, the massive scale of the underlying exploit elevated the retained sum to roughly $48 million, nearing $50 million under prevailing market valuations.

Blockstream’s reaction to the unilateral retention of nearly $50 million was one of clear dissatisfaction. Several hours after the initial technical emergencies were contained—likely allowing legal counsel and executive leadership time to deliberate—Blockstream initiated a new series of on-chain communications. Four distinct encrypted messages were broadcast onto the ledger from Blockstream’s address. An hour later, Blockstream transmitted a fifth encrypted message.

The white-hat party responded to Blockstream’s encrypted outreach with two encrypted messages of their own. Blockstream followed up with one additional encrypted transmission approximately one hour later. Shortly thereafter, the white-hat actor concluded the public exchange by broadcasting a single, highly symbolic character: a frowning sad face emoji ("🙁"). Observers tracking the raw transactions noted that this simple character carried substantial weight, strongly implying that subsequent negotiations regarding a potential reduction or return of the $48 million bounty had broken down. The exchange suggested that Blockstream personnel were deeply dissatisfied with the size of the retained fee, though the exact contents of the encrypted payloads remain confidential.

The broader context of the incident stems from an exploit initially acknowledged by Liquid Network on Sunday. According to the network’s last official public statement, the self-described white hats managed to withdraw approximately 4,000 BTC utilizing the SideSwap peg-out transaction path. Official communications emphasized that the Functionary/Peg-out Account (PAK) hardware and keys were not compromised, that other assets issued on the sidechain remained unaffected, and that the Liquid sidechain had been temporarily paused to prevent further exposure.

Complementing Liquid’s initial statements, SideSwap clarified that the Liquid Bitcoin (L-BTC) involved in the original peg-out anomaly originated from an underlying bug within the Elements code base—the open-source sidechain protocol underpinning the Liquid Network. As of this writing, neither Blockstream nor the Liquid Network administration has issued new public statements regarding the successful recovery of the 3,400 BTC or the ongoing dispute over the retained funds.

The unusual on-chain negotiation process has attracted extensive analysis from blockchain researchers and analysts across the ecosystem. Specialized tracking tools, including a dedicated chat viewer created to visualize the raw OP_RETURN transactions, along with analytical tracking notes compiled by independent researchers such as Sjors on GitHub and Alex Thorn from Galaxy Research, have kept the industry informed of real-time developments. Despite the successful recovery of the vast majority of the network’s Bitcoin reserves, the silent standoff over the remaining $48 million fee indicates that the fallout from the Liquid Network exploit remains far from fully resolved.

Leave a Reply

Your email address will not be published. Required fields are marked *