- Liquid Network recovered 3,400 of the roughly 3,998 BTC drained from its federation wallet on September 6, after the attacker who took it demanded Blockstream patch every bridge node first.
- The remaining 598.5 BTC, worth about $47 million, stayed with the attacker. The return landed in Bitcoin block 965,950 on September 7.
- Blockstream never publicly offered a bounty or agreed to a percentage, before or after the funds moved.
Liquid Network, the Bitcoin sidechain Blockstream has run since 2018, got most of its money back this week. On September 7, an attacker who had pulled roughly 3,998 BTC (about $320 million) out of the network’s federation wallet the day before sent 3,400 BTC back, keeping 598.5 BTC, worth close to $47 million, for itself.
Many are calling that retained slice an unofficial bounty. It is worth being precise about what that word is doing here, because Blockstream never offered one. Compare the recent run of crypto incidents that actually produced negotiated white-hat payouts. Poly Network’s 2021 attacker returned nearly all of a $610 million haul and turned down a formal $500,000 bounty afterward. GMX’s team, during its own $42 million exploit last year, put a 10% figure on the table on-chain before its exploiter returned anything. Team Finance and SafeMoon both saw attackers retain a share, roughly 10% and 20%, that traces back to some agreement between the two sides. In every one of those cases, someone on the victim’s side named a number.
Nobody at Blockstream did that here. Liquid’s own public statements, both before and after the return, stuck to technical language: the withdrawal came through SideSwap’s peg-out key, that key was not compromised, and the company was sorry for the disruption. No bounty, no percentage, no offer. When the attacker signaled it was sending “most” of the funds back and asked, in an on-chain message, whether that was acceptable, Liquid pushed back over the amount through follow-up channels. The reply it got was a single sad-face emoji, and the number did not move. The attacker set its own price and kept it.
The theft itself traces to a bug in Elements, the open-source software Liquid runs on, rather than a stolen private key. SideSwap’s Peg-out Authorization Key processed a technically valid transaction that should not have been possible, and both SideSwap and Liquid have confirmed the key itself was never compromised. Blockstream’s fix took the form of a PGP-signed on-chain message, verified against its published security key, confirming the bridge nodes were patched and it was safe to send the funds back.
Liquid’s bridge remains paused. Minting and burning of L-BTC were still suspended as of September 8, with federation members working through the rest of the patch rollout.
What happens to the 598.5 BTC from here says something about how the next sidechain or bridge operator handles a similar standoff. If Blockstream eventually calls it a bounty, that turns an unagreed-to taking into a retroactive reward. If it does not, and simply absorbs the loss, the lesson for the next attacker is the same either way: nobody has to say yes for the number to stick.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

















