BNB $747.90 -0.09%
XRP $1.39 -1.80%
ETH $2,467.71 -1.46%
BTC $78,433.99 -1.60%
BNB $747.90 -0.09%
XRP $1.39 -1.80%
ETH $2,467.71 -1.46%
BTC $78,433.99 -1.60%
BREAKING
Bitcoin News

Liquid Recovers $270 Million, But 598 Bitcoin Still Missing After Hack

Liquid Gets $270 Million Back But 598 Bitcoin Still Missing After Federation Breach
Liquid Gets $270 Million Back But 598 Bitcoin Still Missing After Federation Breach

Community Trust ScoreVerified

86%
Real
Verified22 votes
Updated 52 minutes ago

Purported white-hat hackers sent roughly $270 million in Bitcoin back to the Liquid Federation wallet. Not all of it, though.

The whole mess started when about 4,000 BTC was pulled from Liquid’s federation wallet — a wallet that originally held around 4,200 BTC. That’s nearly the whole thing, gone in one move. The hackers eventually transferred back 3,400 BTC to the federation’s address, and Blockstream, which supports the Liquid network, confirmed that the bridge nodes hit by the attack have been patched. A network restart is now being prepared, though no firm timeline has been given publicly. Blockstream’s communication method was pretty unconventional — the team reached the hackers by embedding signed messages directly inside Bitcoin transactions. The hackers, for their part, identified themselves as white-hats and said they’d return most of the funds once the vulnerability got fixed. And they did. Most of it.

But 598 BTC is still missing.

Advertisement

The Bug That Started It All

The breach was traced back to a bug in Elements — the open-source software that powers Liquid’s operations. Worth being clear on this: the incident was linked to SideSwap’s Peg-out Authorization Key, but both Liquid and SideSwap have confirmed that the key itself wasn’t compromised. The real problem was the bug sitting inside Elements. That’s a meaningful distinction, because it shifts the blame away from key management failures and toward a software-level flaw that probably went undetected through normal review cycles.

Blockstream has been pushing software updates across the network and working directly with federation members to coordinate a restart. The company wants all nodes running the patched version before anything goes live again. A chain split resolution is also underway, which adds another layer of technical complexity to an already messy situation. No one’s rushing this, it seems.

JAN3 CEO Samson Mow told users to hold off on sending Bitcoin to Liquid peg-in addresses until the network is confirmed fully operational. Simple enough advice, but it matters — anyone moving funds into a paused network risks getting stuck in limbo with no clear recourse.

White-Hat Claims Draw Skepticism

Not everyone’s buying the ethical hacker story. Charles Guillemet, CTO of Ledger, went on record with doubts. His read: if the 598 BTC that hasn’t come back is some kind of negotiated reward, that’s basically extortion — not white-hat behavior. He’s got a point. The line between “we kept a fee for finding your bug” and “pay us or we don’t return your funds” is thin, and the framing matters a lot for how the crypto industry processes incidents like this one.

Neither Blockstream nor Liquid has publicly commented on any repayment terms. No one’s called it a bounty. No one’s confirmed there’s a deal in place. Cointelegraph tried to get comments from both companies before publication and didn’t hear back.

That silence is doing a lot of work here. Without a clear statement, the 598 BTC sits in an awkward legal and ethical gray zone. Did the hackers keep it as compensation? Is Blockstream quietly accepting that as the cost of getting 3,400 BTC returned? Unclear. And the longer there’s no public disclosure, the more room there is for speculation about what actually happened behind the scenes.

What the Incident Means for Liquid Users

Liquid is a Bitcoin sidechain built for faster, more confidential transactions — it’s used by exchanges, traders, and institutions that need settlement speed that the base Bitcoin layer can’t always provide. A security event of this scale isn’t just a technical headache. It’s a trust problem. Federation-based sidechains depend on users believing the federation members can keep funds safe. When 4,000 BTC walks out the door in a single incident, that belief takes a hit, regardless of how much comes back.

The hackers’ decision to return funds was, per what Blockstream shared, contingent on the vulnerabilities being patched and all nodes confirmed updated. So the return wasn’t unconditional — there were terms, even if those terms weren’t made public. That’s a strange dynamic. The network’s restart was essentially held hostage, at least partially, to the satisfaction of people who took the funds in the first place.

Blockstream has been proactive in the technical response, by most accounts. Updates are being deployed. Federation members are being coordinated. The chain split is being resolved. But the reputational work is harder and slower than any software patch.

And the 598 BTC question won’t go away on its own. Guillemet’s framing — that keeping unreturned funds looks like extortion — is probably the view a lot of people in the industry quietly share, even if they’re not saying it publicly. Whether Blockstream addresses that directly, or just lets the network restart and moves on, will shape how this incident gets remembered.

For now, Liquid stays paused. Users wait. And 598 BTC sits somewhere unaccounted for, with no public explanation from the people who took it or the federation that lost it.

Frequently Asked Questions

How much Bitcoin was returned after the Liquid network security incident?

Approximately 3,400 BTC, worth around $270 million, was returned to the Liquid Federation wallet. Around 598 BTC remains unreturned as of the latest available information.

What caused the Liquid network breach?

The breach was traced to a bug in Elements, the open-source software underlying Liquid’s operations. SideSwap’s Peg-out Authorization Key was linked to the incident, but both Liquid and SideSwap confirmed the key itself was not compromised.

Who warned users about sending Bitcoin to Liquid during the incident?

JAN3 CEO Samson Mow advised users to avoid sending Bitcoin to Liquid peg-in addresses until the network is confirmed fully operational again.

Why It Matters

This incident highlights the ongoing vulnerabilities within cryptocurrency infrastructure, particularly in federated models, where a single breach can result in substantial losses. The return of $270 million, while significant, underscores the complexities of recovering stolen assets in the crypto space and raises questions about the security measures of decentralized networks. As the market continues to grapple with security challenges, such breaches could impact investor confidence and affect the adoption of similar technologies.

Community Trust IndexHigh Confidence
86%
Real
Real86%14%Fake
22 community signals

Dan Saada

Dan Saada holds a Master of Finance from ISEG Business School (France). With years of experience covering digital assets, Dan specializes in cryptocurrency market analysis, blockchain technology, and decentralized finance.

Advertisement

Related Stories