Liquid Attacker Broadcasts Return Of 3,400 BTC, Keeps 598
Following a theft of nearly 4,000 bitcoin from Blockstream's Liquid federation wallet, the attacker has broadcast a transaction returning 3,400 BTC while retaining approximately 598 BTC. The exchange between the attacker and Blockstream took place entirely through blockchain messages, with Blockstream indicating the return was acceptable after patching compromised systems.
Why It Matters
This incident highlights both the vulnerabilities in cryptocurrency infrastructure and an emerging negotiation method conducted through immutable blockchain transactions. The return of the majority of stolen funds suggests the attacker may have been motivated by responsible disclosure rather than traditional theft, though the underlying vulnerability in the Elements software used by Liquid points to ongoing security challenges in the cryptocurrency ecosystem.
Key Facts
- Amount returned: 3,400 BTC (approximately $268 million)
- Amount retained by attacker: 598.50 BTC (approximately $47.2 million or 15% of total)
- Original theft amount: 3,998.50 BTC
- Cause: Bug in Elements software that created counterfeit L-BTC
- Communication method: PGP-signed messages embedded in blockchain transactions
Blockstream's Liquid sidechain experienced a significant security incident when approximately 4,000 bitcoin were withdrawn on Sunday through a vulnerability in the underlying Elements software. The attacker subsequently began communicating with Blockstream using an unconventional method: cryptographically signed messages embedded directly into blockchain transactions via OP_RETURN fields.
The negotiation unfolded rapidly across the blockchain. Blockstream initiated contact on Sunday evening with a request to reach out to its security team. After encrypted messages were exchanged early Monday, the attacker responded by committing its entire balance to itself and asking whether returning most of the funds to the federation wallet would be acceptable. Blockstream responded affirmatively and confirmed that bridge nodes had been patched and secured.
At 11:46 UTC on Monday, the attacker broadcast the return transaction sending 3,400 BTC back to the Liquid federation address while retaining 598.50 BTC, equivalent to roughly 15 percent of the stolen amount. The transaction remained unconfirmed but was flagged as replaceable. Notably, neither party published any explicit statement characterizing the retained amount as a bounty or setting formal recovery terms, leaving the arrangement ambiguous.
SideSwap, a Liquid Federation member whose peg-out authorization key facilitated the theft, identified the root cause as a bug in Elements software that allowed the creation of counterfeit L-BTC tokens. The company clarified that its own systems and cryptographic keys were not compromised, and that it had processed the transaction as it would any legitimate withdrawal request.
The Liquid network remains in a secured state with bridge nodes still disabled to prevent new transactions from reaching the sidechain. The federation's bitcoin peg stands at 197.47 BTC confirmed, which would rise to 3,597.47 BTC if the return transaction achieves confirmation. Blockstream and Liquid have issued no public statements beyond their initial incident notification, while the attacker's address has become a public message board hosting unverified claims and promotional content from various parties.
Keep Reading

Bitcoin’s golden cross is here

Hunter Biden wants to launch a LAPTOP memecoin. Crypto traders hate it already

Bit2Me sets up specialized unit to help law enforcement track down crypto assets
