Advertisement
AD

Liquid Hackers to Return 'Most' of 4,000 BTC After Bug Fix

Mon, 7/09/2026 - 6:09
The purported white-hat hackers behind the $320 million Liquid Network security incident have offered to return "most" of the nearly 4,000 BTC they withdrew, but only after Blockstream fixes the vulnerability that enabled the exploit.
Advertisement
Liquid Hackers to Return 'Most' of 4,000 BTC After Bug Fix
Cover image via depositphotos.com
Google
Advertisement

The purported white-hat hackers behind the roughly $320 million Liquid Network security incident are willing to return "most" of the nearly 4,000 BTC they withdrew.

The unusual pledge was made during an ongoing on-chain conversation between the unidentified actors and Blockstream, according to Galaxy Research head Alex Thorn.

A makeshift communication channel 

The two sides have been communicating through Bitcoin OP_RETURN messages as well as PGP-encrypted text.  

HOT Stories
Liquid Hackers to Return 'Most' of 4,000 BTC After Bug Fix XRP, Solana (SOL), Hyperliquid (HYPE) and Bitcoin (BTC) Price Analysis for September 7: Unconventional Market Picture

The episode began on Sunday after approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. It accounts for roughly 95% of the Bitcoin that had been pegged into the sidechain. 

Advertisement

Liquid subsequently disabled its bridge nodes and paused the network.

Roughly $320 million worth of funds were then consolidated into a Bitcoin address alongside a message declaring: "we are whitehats. contact us on chain."

You Might Also Like
Advertisement

Notably, Liquid itself has so far described those responsible only as "purported" white-hat hackers.

Patching the bug 

According to Thorn’s reconstruction of the on-chain exchange, Blockstream attempted to establish contact at Bitcoin block 965,822 by sending 1,000 satoshis alongside an OP_RETURN message to alert the security team. 

A subsequent transaction contained encrypted material addressed to the holder’s key together with a PGP signature. Thorn said the signature could be verified against Blockstream’s published public key. 

The hackers later responded in block 965,869 by moving their own balance and directing 1,000 satoshis to the federation’s peg wallet.

Their accompanying message asked whether sending "most" of the funds back to the federation address would be acceptable. 

The hackers told Blockstream that they would not return the Bitcoin until the damning vulnerability had been fixed across the network. "Please fix the bug first," they said.

The hackers’ use of the word "most" leaves open the question of how much Bitcoin they intend to retain.

There is also no guarantee that they will follow through on the pledge.

Ledger Chief Technology Officer Charles Guillemet initially claimed that conventional white hats generally do not drain hundreds of millions of dollars from a bridge. He compared the situation with previous crypto exploits such as Ronin and Euler. 

Guillemet later changed his tune after the hackers attempted to communicate.

Criminal groups do not typically make efforts to establish contact with their victims.

"There’s hope," he wrote, arguing that these could be researched using powerful AI systems to locate the vulnerability without proper disclosure procedures. 

For now, however, almost all of the Bitcoin remains under the hackers’ control.

Advertisement
Advertisement
Advertisement
Advertisement

Recommended articles

Our social media
There's a lot to see there, too
Advertisement
Advertisement
AD