The security incident that froze Liquid Network in early September has shifted from emergency software response to a dispute over hundreds of bitcoin that have not been returned.
On September 11, Blockstream said it would not pay the terms demanded by the party behind the exploit. About 598.5 BTC remain under the exploiter's control after 3,400 BTC were sent back.
No federation key was stolen
One of the stranger details is what apparently did not happen. Liquid says its federation keys were not compromised, and SideSwap says its Peg-out Authorization Key was not compromised either.
The vulnerability instead existed in Elements, the open-source software underlying Liquid.
According to the post-incident account, the bug allowed approximately 4,000 L-BTC to be created without the bitcoin reserves that should normally back them.
Those unbacked L-BTC were then sent through SideSwap's ordinary peg-out flow. The tokens were burned through an authorized operation, after which the Liquid Federation released roughly 3,996 real BTC to the destination address.
The final withdrawal therefore looked legitimate to the peg-out mechanism. The invalid state had been created earlier.
Almost the entire bitcoin reserve was drained
Liquid disclosed the incident on September 6 after roughly 4,000 BTC had left a federation wallet holding around 4,200 BTC.
At the time, the withdrawn bitcoin was worth approximately $320 million and represented roughly 95% of the reported reserve.
Bridge nodes were disabled and exchanges were asked to suspend L-BTC deposits and withdrawals. With no new transactions being submitted, the Liquid sidechain was effectively paused.
Other assets issued on Liquid were not directly exploited, according to the network, although users of those assets were still affected by the shutdown.
The exploiter told Blockstream to patch first
Communication took place onchain through Bitcoin OP_RETURN messages and PGP-encrypted text.
The party described itself as a white hat and told Blockstream to fix the underlying bug and make sure all relevant nodes were patched before most of the bitcoin would be returned.
Blockstream later sent a signed message stating that the bridge nodes had been patched and that the funds could safely be returned.
The exploiter then transferred 3,400 BTC back to the federation address.
At that stage, the episode still looked like an extremely aggressive form of security disclosure followed by substantial restitution.
The remaining 598.5 BTC changed the story
The full balance did not come back.
Approximately 598.5 BTC remained with the exploiter. SideSwap separately returned about 4 BTC in fees it had collected while processing the original peg-out.
The exploiter subsequently demanded a bounty equal to 10% of the incident.
That is where the white-hat framing becomes difficult. Responsible disclosure can involve negotiated compensation. Holding tens of millions of dollars in someone else's assets until a demanded percentage is paid is a very different arrangement.
Blockstream says it will not pay
Blockstream rejected the demand on September 11.
The company says it had attempted to recover the funds in good faith but no longer considers withholding the remaining bitcoin compatible with responsible disclosure.
It has indicated that recovery efforts will continue with law enforcement and blockchain-forensics specialists.
There is also a precedent problem. Paying a fixed percentage after an exploit of this scale could create an obvious incentive structure: take the funds first, call the operation a white-hat intervention later, and use the assets themselves as leverage in a bounty negotiation.
Elements 23.3.4 contains the fix
Blockstream deployed Elements 23.3.4 on September 9 as part of the remediation.
Liquid resumed block production on September 10, and transactions started flowing again later that day.
Recovery is not completely finished. Peg-outs remain disabled as a precaution while the BTC/L-BTC reserve is restored.
That distinction matters. A chain producing blocks again does not mean every bridge operation has returned to normal.
The exploit hit the core assumption behind L-BTC
L-BTC is intended to represent bitcoin held against it by the Liquid Federation.
The incident therefore went beyond an ordinary wallet theft. A software flaw allowed a large quantity of L-BTC to exist without corresponding backing, after which the standard withdrawal mechanism was used to extract real BTC from the reserve.
Preventing exactly that mismatch is fundamental to a pegged asset.
The fact that no private key was stolen is technically important, but it does not remove the economic problem. A reserve-backed system depends on the rules governing asset creation just as much as it depends on the keys guarding the reserve.
The $320 million headline no longer describes the current loss
Calling this a $320 million hack still captures the scale of the original withdrawal, but it no longer describes the amount currently outstanding.
About 3,400 BTC have been returned, and SideSwap returned the roughly 4 BTC it earned in fees. The unrecovered balance is now concentrated around 598.5 BTC.
The opposite simplification would also be misleading. Focusing only on the bitcoin still missing would obscure the fact that a software vulnerability was able to drain nearly the entire reported reserve and force the network offline.
What remains is increasingly a legal question
The software has been patched. Blocks are being produced again. Most of the bitcoin has been recovered.
What remains looks less like incident response and more like a dispute over money being held as leverage.
“White hat” is not a legal status that someone grants themselves in an onchain message. It normally describes security work intended to expose and repair a vulnerability without permanently appropriating the assets at risk.
With 598.5 BTC still withheld and a 10% payment demanded for their return, Blockstream has decided that the incident no longer fits that description.