A major reversal has occurred in the incident involving the abnormal outflow of nearly 4,000 BTC from the Bitcoin sidechain Liquid Network. The party claiming to be a “white-hat hacker” has returned 3,400 BTC to Liquid Federation. Estimated at the value based on the exchange rate at the time of transfer, this is worth about $269 million, equivalent to recovering roughly 85% of the funds. However, around 598.5 BTC, worth approximately $47 million, remains in the counterparty’s controlled addresses, and the incident has not yet fully ended.

SideSwap indicates that at 14:05 on September 6 (UTC), a customer sent 4,000 L-BTC to its peg-out service. The system destroyed the L-BTC according to normal procedures and obtained a valid peg-out authorization. About 23 minutes later, Liquid Federation paid approximately 3,996 BTC to the relevant address on the Bitcoin mainnet.

What initially shocked the market was that the Liquid Federation wallet originally held about 4,200 BTC; one anomalous expenditure involved about 95% of the reserves. Estimated at the BTC price at the time of about $80,000, the scale was close to $320 million.

However, the incident reversed quickly within a day.

The Block and on-chain records show that after Blockstream patched the relevant bridge nodes, it informed the incident party via an on-chain message that the issue had been fixed. Afterwards, at Bitcoin block height 965,950, the other party transferred exactly 3,400 BTC back to the Liquid Federation address.

Based on the event settlement amount of approximately 3,998.5 BTC, the return ratio is about 85%. The incident that may have caused an asset shortfall of over $300 million has now had most of its funds recovered.

Why are 598.5 BTC still left behind?

The biggest question turns to the remaining 598.5 BTC.

On-chain transactions show that after the incident party returned 3,400 BTC, about 598.5 BTC continued to return to its controlled address as change. Based on the price at the time of the incident, the value is about $47.3 million.

The incident party previously claimed to be “whitehats” via a Bitcoin OP_RETURN message, and asked Blockstream to first patch the vulnerability, and only after confirming that all nodes are secure would it return the funds.

Later, Blockstream also sent an on-chain message with a PGP signature stating: “Bridge nodes are patched, safe to return the funds.” Then, only after that, the 3,400 BTC was truly sent back.

This caused the incident, initially viewed as a $320 million “hacker attack,” to gradually turn into a very unusual on-chain vulnerability disclosure and a funding negotiation. But the problem is: there is currently no public evidence showing that Blockstream agreed to let the other party keep nearly 600 BTC as a bounty for the vulnerability.

Ledger CTO Charles Guillemet also publicly questioned that if this nearly 600 BTC was never established in advance through an agreement as a legitimate bug bounty, then even if 85% of the funds are returned and the remaining funds are kept by the party themselves, it would be difficult to define it simply as a traditional “white-hat hacker” action.

Image source: X/@P3b7_

The real vulnerability is not that the SideSwap keys were stolen

Another major turning point in the incident is that the initial speculation that “the private keys were stolen” is currently not supported.

Liquid and SideSwap both said that the incident used SideSwap’s valid Peg-out Authorization Key (PAK), but that key itself was not compromised, and none of the other Federation keys were breached.

According to SideSwap’s disclosure, Blockstream later confirmed that the problem originated from a vulnerability in the Elements software used under Liquid, which allowed problematic L-BTC to be created. For SideSwap, these L-BTC are not meaningfully different from normal L-BTC at the system level, so its peg-out service processed the transactions according to the established procedure.

Liquid’s normal design is: 1 BTC locked into the Federation → mint 1 L-BTC; during redemption: destroy 1 L-BTC → Federation releases 1 BTC. Liquid’s official documentation also clearly states that, in theory, every L-BTC should be supported 1:1 by an equal amount of BTC.

The real issue exposed by this incident is that if the system allows “L-BTC without corresponding BTC reserves” to enter the normal peg-out procedure, then even if all keys signed by the PAK and the Federation are safe, real BTC could still be released through transaction processes that look legitimate. This is also the most worth studying aspect of this incident for the security architecture on Bitcoin’s sidechain.

Liquid has not yet fully returned to normal

The return of 3,400 BTC greatly reduced the asset shortfall, but it does not mean the incident is already over.

As of the latest publicly available information, Liquid has not yet confirmed whether the remaining roughly 598.5 BTC will continue to be returned, nor has it publicly stated that this fund is a vulnerability bounty agreed upon by both parties.

After the incident, Liquid closed the bridge nodes and asked exchanges to temporarily suspend L-BTC deposits and withdrawals; SideSwap’s swap, peg-in, and peg-out services were also paused. The latest report indicates that Liquid has not yet published the exact timeline for when its services will fully return to normal.

Therefore, the market still needs to watch three things next: first, whether the remaining 598.5 BTC will be returned; second, when Blockstream will release a complete Elements vulnerability technical report; and third, whether Liquid can re-confirm the completeness of the 1:1 L-BTC reserve and restore peg services.

Judging purely from the funding outcome, the Liquid incident has clearly reversed.

At first, about 4,000 BTC, worth about $320 million, flowed out from the Federation wallet, and it once involved nearly 95% of the BTC reserves. Now, 3,400 BTC has been returned, shrinking the amount not recovered to about 598.5 BTC. But the issues left behind by this incident may be more important than the loss amount.

Liquid is a Bitcoin sidechain that relies on a Federation to maintain two-way pegging of BTC. This incident shows that even if the core keys holding BTC were not compromised, a software verification vulnerability higher up in the stack could still cause the normal security mechanisms to “correctly execute a wrong transaction.” Returning the 3,400 BTC resolved most of the asset shortfall, but it did not resolve this architectural problem.

What Liquid truly needs to answer is why, in a system where no keys were compromised, it could still release nearly the entire Federation reserve in one event.

  • This article is reprinted with authorization from: (Block Chain).

  • Original title: (Liquid Network event reversal: 3,400 BTC returned, around 600 BTC still not returned)

  • Original author: Anfei

“Bitcoin sidechain Liquid hacked case reversed: hacker returns 3,400 BTC, about 600 BTC still not returned” was first published on “Crypto City.”