About 95% of the reported reserve left
Liquid Network disclosed the security incident on September 6. Approximately 4,000 BTC, worth about $320 million at the time, had been withdrawn from its federation wallet.
That wallet reportedly contained around 4,200 BTC beforehand, putting the initial outflow close to 95% of its bitcoin holdings.
Liquid disabled bridge nodes and exchanges were asked to suspend L-BTC deposits and withdrawals. The sidechain was effectively paused.
Bitcoin itself continued operating normally.
The authorization key apparently worked as designed
Liquid said the funds left through SideSwap's Peg-out Authorization Key. Crucially, it said that key was not compromised. SideSwap has similarly said neither its systems nor its authorization key were breached.
SideSwap says a customer submitted 4,000 L-BTC to its peg-out service at 14:05 UTC. The L-BTC was burned using a valid authorization.
Twenty-three minutes later, the Liquid Federation released roughly 3,996 actual BTC to the requested Bitcoin address.
From the peg-out system's perspective, much of that process apparently looked legitimate.
The invalid value may have been created earlier
SideSwap says Blockstream later determined that the L-BTC used for the withdrawal had been generated through a bug in Elements, the open-source software underlying Liquid.
That changes how the incident should be understood.
Instead of stealing the key that controls bitcoin withdrawals, the actors appear to have obtained L-BTC that was not backed by corresponding bitcoin and then presented those tokens to a legitimate peg-out process.
The L-BTC was burned and real BTC left the federation wallet in return.
As of September 8, Blockstream had not published a complete technical post-mortem explaining the underlying vulnerability in enough detail to independently reconstruct the entire exploit chain.
A sidechain peg depends on one very important equation
Liquid represents bitcoin on its sidechain as L-BTC. Users normally lock bitcoin through the peg and receive an equivalent amount of L-BTC.
Going back in the other direction destroys L-BTC and releases the corresponding bitcoin.
The economic promise is therefore straightforward: each legitimate L-BTC should correspond to bitcoin held for redemption.
If an attacker can create L-BTC without supplying the matching BTC, that accounting relationship breaks. The attacker has effectively created a claim against the reserve without first funding it.
A perfectly valid withdrawal mechanism can then become the final step of the exploit rather than the vulnerable component itself.
The attackers called themselves white hats on-chain
After the withdrawal, a Bitcoin transaction carried a short message identifying the actors as white hats and asking Blockstream to contact them on-chain.
What followed was an unusually public negotiation conducted through Bitcoin OP_RETURN messages and PGP-signed or encrypted communications.
The group told Blockstream to fix the bug and ensure the affected nodes were patched before it would return most of the bitcoin.
Blockstream later sent a signed message saying its bridge nodes had been patched and that the funds were safe to return.
The promised transfer followed.
3,400 BTC came back
A transaction confirmed in Bitcoin block 965,950 returned exactly 3,400 BTC to a Liquid Federation address.
That recovered about 85% of the bitcoin involved in the incident.
The transaction left approximately 598.5 BTC under the actors' control. At prices around September 8, the remaining balance was worth roughly $47 million.
There has been no public confirmation that Blockstream agreed to let the group retain that amount as a bug bounty.
Calling the actors white hats therefore requires an important qualifier: that is how they describe themselves. Their status has not been independently established.
Keeping $47 million complicates the white-hat story
Ledger CTO Charles Guillemet publicly challenged the description while nearly 600 BTC remained with the group.
The distinction is not semantic trivia. Authorized security researchers can receive substantial bug bounties, particularly for flaws capable of putting hundreds of millions of dollars at risk.
But no public terms currently establish that retaining 598.5 BTC was an agreed reward in this case.
Recovering 3,400 BTC materially improves the situation. It does not settle the relationship between Blockstream and the people who moved the funds.
Getting the money back did not immediately restart Liquid
Blockstream's patch confirmation came before the 3,400 BTC return, but the network remained paused afterward.
As of September 8, public bridge nodes were still listed as unavailable while federation members prepared a coordinated restart. Users were being warned not to send BTC to Liquid peg-in addresses until restoration was confirmed.
Liquid said other issued assets such as USDT, DePix and real-world assets were not directly affected by the security incident, although the network interruption still limits normal operations.
This was not a Bitcoin protocol failure
Nothing in the incident indicates that Bitcoin's consensus rules were broken or that attackers created thousands of native BTC from nothing.
The bitcoin sent out of the federation wallet was real bitcoin moved through valid Bitcoin transactions.
The apparent failure happened in the system responsible for maintaining the relationship between those BTC and the L-BTC circulating on Liquid.
That is why bridges and pegs remain such sensitive infrastructure. An attacker does not need to break the base blockchain if another system can be persuaded that an illegitimate redemption request is legitimate.
The final accounting still needs two numbers and one explanation
The largest part of the reserve has returned, which is the immediate good news.
Liquid still needs to resolve the roughly 598.5 BTC that remains outside the federation wallet, restore normal bridge operation and publish enough technical detail to establish exactly how the Elements flaw worked and how broadly it could have been exploited.
Even a complete recovery would not make this incident unimportant.
The most revealing security failures are not always the ones where a key is stolen. Sometimes every signature is valid, every withdrawal looks authorized, and the catastrophic mistake happened several steps earlier.