Following on-chain negotiations, the white-hat group that withdrew nearly 4,000 bitcoin from the Liquid Network federation wallet on Sunday sent back 3,400 BTC on Monday. Approximately 598 BTC—amounting to 15% of the total consolidated sum—remained at the original holder address as an implied bounty fee valued at $48 million.
The return transaction (bc49a46d) achieved confirmation at 16:09 UTC on September 7, depositing precisely 3,400 BTC back into the designated Liquid peg script address while routing 598.5 BTC back to the white-hat hacker address as change.
This transfer came after a full day of communication inscribed directly into Bitcoin blocks. The white-hat actors initiated the on-chain dialogue via a transaction featuring an OP_RETURN arbitrary data field reading “contact us on chain,” sent straight from the address that held the 4,000 BTC taken from the Liquid Network.
A Blockstream-linked address responded with “Please contact security@blockstream.com”. Subsequent notes from that sender included Electrum-encrypted payloads alongside PGP signatures verifiable against Blockstream’s publicly released security key.
In block 965869, the white-hat participants used clear text to ask if returning “most” of the funds to the federation script would be acceptable. The 1,000-satoshis output attached to that transaction served strictly as a message carrier.
Shortly thereafter, the white hats instructed, “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” appending an encrypted text block matching Blockstream’s PGP key.
Within the same block, a clear-signed response from the Blockstream sender stated, “Yes, thank you.” Hours later, that same Blockstream entity issued another clear-text message reading, “Bridge nodes are patched, safe to return the funds.”
Minutes after the 3,400 BTC arrived, the white hats returned 85% of the assets while retaining 15% as an implied finder’s fee. Observers on X praised the move as preferable to losing 100%, though others expressed surprise at the sheer magnitude. While 15% may sound standard, the total sum approaches $50 million at current market prices. Blockstream appeared displeased with the fee size, as four encrypted on-chain messages followed a few hours later—likely after office hours concluded and legal counsel weighed in—with an additional encrypted message posted by Blockstream an hour afterward.
The white hats responded with two encrypted messages, prompting a single reply from Blockstream an hour later. The white hats then published a simple, telling “
” sad face emoji. This expression implies that discussions regarding a reduction in the bounty size stalled. Blockstream participants appear thoroughly frustrated regarding the finder’s fee. The exact contents of those encrypted messages remain unknown, and Blockstream has issued no public statements addressing the matter, suggesting this saga may not be concluded.

The entire chat log can be tracked easily via a vibe-coded site created by the author. Additional researchers monitoring the conversation and on-chain data include Sjors via a GitHub gist and Alex Thorn from Galaxy Research.
Liquid’s Sunday statement remains the network’s final official account update: the alleged white hats withdrew about 4,000 BTC via the SideSwap peg-out path, the PAK itself remained uncompromised, other issued assets stayed safe, and the sidechain was temporarily paused. Neither Liquid nor Blockstream issued a new statement regarding the 3,400 BTC return as of this writing. SideSwap previously stated that the L-BTC involved in the original peg-out “came from an Elements bug.”
Frequently Asked Questions
How much bitcoin was returned to the Liquid Network?
The white-hat group returned 3,400 BTC to the Liquid Network federation wallet.
How much did the white hats keep as a bounty?
They kept 598.5 BTC, which represents roughly 15% of the total funds withdrawn, valued at approximately $48 million.
How did the communication take place?
The negotiations were conducted on-chain using OP_RETURN arbitrary data fields within Bitcoin blocks, alongside PGP-signed and encrypted messages.
What caused the initial withdrawal?
SideSwap noted that the L-BTC involved in the original peg-out originated from an Elements bug.


