TechNewsReel
Live

Blockstream Rejects Bounty Demands After Liquid Network Hackers Return 3,400 BTC

The recovery of 85% of stolen funds prevents a total peg collapse, but a standoff remains over the final 600 BTC.

TechNewsReel Newsroom · September 11, 2026

Purported white-hat hackers drained approximately 4,000 BTC from the Blockstream Liquid Network federation wallet on a Sunday. The incident, involving assets valued at roughly $320 million, triggered an immediate security response and a subsequent standoff over the remaining funds.

Following the initial theft, the attackers identified themselves as white-hats via an OP_RETURN message, stating, "we are whitehats, contact us on chain." After negotiations and the application of security patches to bridge nodes, the attackers returned 3,400 BTC to the Liquid Federation. However, the resolution remains incomplete, as the attackers continue to hold approximately 598.5 BTC. Blockstream has since formally rejected demands for a bounty payment in exchange for the remaining assets.

The Sidechain Vulnerability

The Liquid Network operates as a Bitcoin sidechain, utilizing a federation of nodes to manage the pegging of Bitcoin into L-BTC. The theft targeted the federation wallet that backs these assets, exposing a critical vulnerability in the bridge infrastructure. To mitigate further losses and secure the system, Blockstream was forced to temporarily disable bridge nodes and pause the sidechain. This pause allowed engineers to deploy necessary security patches to the federation's architecture before the return of the majority of the funds.

Industry Implications

This breach underscores the inherent risks associated with sidechain federation models, where the security of pegged assets relies on a limited set of trusted nodes rather than the full Bitcoin network. While the recovery of 85% of the drained funds prevents a total collapse of the L-BTC peg, the incident highlights a growing tension in the crypto industry between corporate entities and independent security researchers. The refusal to pay a bounty for the final 600 BTC signals a hardline approach to "white-hat" activity that begins with an unauthorized withdrawal of funds.

Unresolved Losses

Despite the partial recovery, the remaining 598.5 BTC represents a significant unresolved loss and a likely point of legal and forensic contention. Market participants are now watching to see if the attackers will move the remaining funds or if Blockstream will pursue further recovery efforts. The incident serves as a stark reminder that even established sidechains remain susceptible to high-impact exploits, leaving the industry to debate the boundaries of ethical hacking and the necessity of formalized bug bounty programs for critical infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.