Liquid Network recovered 3,400 BTC worth about USD 268 million on Monday after a weekend exploit drained roughly 4,000 BTC from its reserves. About 600 BTC, or 15% of the withdrawn amount, remains with the attacker. L-BTC deposits and withdrawals remain suspended as operators work toward a safe restart.
Liquid disclosed the attack on September 6 and said stolen private keys did not cause the incident. SideSwap also said attackers did not breach its systems during the event.
Instead, the vulnerability appears to have come from Elements, the Bitcoin Core fork that powers Liquid. A range-proof verification cache bug apparently allowed creation of L-BTC without matching Bitcoin backing.
The attacker then used those unbacked tokens to obtain real BTC through Liquid’s normal peg-out process. Liquid took its federation wallet and bridge nodes offline after detecting the abnormal withdrawals.
The self-described white-hat hacker pledged to return most funds after Blockstream fixed the underlying software flaw. In messages to Blockstream, the party requested patches across every node before returning Bitcoin.
Blockstream later said its bridge nodes had received the patch and could safely accept the funds. Onchain data then showed 3,400 BTC moving back to the Liquid Federation wallet.
About 598.5 BTC remains under the actor’s control. No public agreement explains whether those coins represent a bounty or whether the party plans another return.
Ledger Chief Technology Officer Charles Guillemet questioned the white-hat label after the partial repayment. He said keeping approximately 600 BTC did not fit a genuine bug-bounty arrangement and described it as closer to extortion.
The return removed most of the immediate reserve shortfall, but it did not restore normal Liquid operations. The network still needs to verify backing and complete software deployment before reopening its bridge.
Also Read: Pi Network Climbs Toward USD 0.085 as Low Liquidity Boosts PI Recovery
Liquid has not resumed normal operations while its operators prepare a safe restart. L-BTC deposits and withdrawals remain halted, including related services at centralized exchanges. Meanwhile, Bitcoin’s main network continues operating without disruption. The exploit also left other Liquid-issued assets untouched, including USDT, Depix, and real-world assets.
Liquid wallets such as Aqua face disruption only across their Liquid functions. Users can therefore access unaffected Bitcoin network services, while Liquid peg activity remains unavailable.
Before reopening the bridge, operators need to restore one-to-one backing for legitimate L-BTC. They also need to distribute the patched Elements release across the network and verify safe bridge operation. Liquid has not explained how it will cover any remaining gap in L-BTC backing. The network also has not published a timeline for restoring the sidechain and its peg services.