Key Points
- Purported white-hat hackers returned 3,400 BTC worth roughly $270 million to Liquid’s federation wallet after withdrawing about $320 million.
- The returned Bitcoin represents approximately 85% of the funds taken, while about 598 BTC remains outstanding as Blockstream continues engaging with the actors.
- Liquid remains paused as Blockstream and federation members complete security fixes, address a chain split and prepare for a coordinated restart.
Liquid Recovers Most of Bitcoin Withdrawn in Security Incident
Liquid has recovered most of the Bitcoin withdrawn during a major security incident after purported white-hat hackers returned 3,400 BTC to the Bitcoin sidechain’s federation wallet.
The returned Bitcoin was worth approximately $270 million at the reported valuation. It follows the withdrawal of roughly 4,000 BTC from a federation wallet that held about 4,200 BTC, temporarily removing a significant portion of the reserves backing Liquid’s Bitcoin-pegged asset.
Onchain records confirmed that exactly 3,400 BTC was transferred back to the federation wallet.
JAN3 CEO Samson Mow said the return came after Blockstream confirmed that the affected bridge nodes had been patched. Approximately 598 BTC remains outstanding, with Blockstream continuing discussions with the actors.
Liquid Remains Paused During Security Recovery
Liquid’s network has not yet resumed operations. Blockstream said updated software had been deployed and federation members were preparing for a coordinated restart.
Liquid issues L-BTC against Bitcoin held by its federation. The recovery of approximately 85% of the withdrawn BTC therefore restores much of the Bitcoin backing affected by the incident, although the remaining balance means the security response is not yet complete.
Mow said additional fixes and security improvements were still being implemented, alongside efforts to resolve a chain split before the network can safely restart.
Users have also been advised not to send Bitcoin to Liquid peg-in addresses until the restart is officially confirmed. No other user action was required, according to Mow.
Vulnerability Linked to Elements Software
The original withdrawal was processed through SideSwap’s Peg-out Authorization Key, although both Liquid and SideSwap said the key itself was not compromised.
Instead, SideSwap attributed the incident to a bug in Elements, the open-source software that underpins Liquid.
Blockstream subsequently contacted the actors through signed messages embedded in Bitcoin transactions. The individuals described themselves as white hats and indicated that most of the withdrawn funds would be returned after the vulnerability was fixed and federation nodes had installed the required patch.
The incident therefore illustrates the complicated role of responsible disclosure in decentralized financial infrastructure, where recovering assets can depend not only on technical remediation but also on negotiations conducted directly onchain.
Debate Over the “White Hat” Label
Despite the substantial return, questions remain over how the actors should be classified.
Ledger Chief Technology Officer Charles Guillemet challenged the white-hat characterization, arguing that retaining roughly 600 BTC could resemble extortion if the amount represented a negotiated reward for returning the funds.
Neither Blockstream nor Liquid has publicly characterized the outstanding Bitcoin as a bounty or disclosed specific repayment terms.
That leaves the final resolution uncertain even as most of the stolen funds have been recovered. For Liquid, the immediate priority remains restoring network integrity before reopening Bitcoin peg-in and peg-out operations.
Outlook
The return of 3,400 BTC significantly reduces the financial impact of the Liquid incident, but the network’s restart remains dependent on completing the security response. The episode also highlights the risks surrounding bridge infrastructure and the importance of coordinated software updates across federation members. Until Liquid confirms that its systems are secure and operations have resumed, the recovery should be viewed as a major step in the incident response rather than a full resolution.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible