Claim of 3,400 BTC Returned on Liquid Network – Where's the Proof?
2026-09-08
Liquid Network, Blockstream's Bitcoin sidechain, just had a dramatic weekend. The news of the return of 3,400 BTC was widely reported across crypto media, but behind that big number lies a more fundamental question: can the entire process be verified through on‑chain data, or is some of the information still just a one‑sided claim from the perpetrator?
This question is important, given that not all media reports agree on how strong the available evidence currently is.
Key Takeaways
- Liquid Network's federation wallet lost approximately 4,000 BTC (~$320 million) on 6 September 2026 due to a bug in the Elements code that allowed L‑BTC to be minted without backing.
- The perpetrator returned 3,400 BTC (~$268–269 million) on 8 September via traceable on‑chain transactions, but still holds about 600 BTC (~$47 million) with no publicly announced bounty agreement.
- Ledger CTO Charles Guillemet and former Blockstream CSO Samson Mow have openly questioned the perpetrator's "white hat" claim, describing the pattern as more akin to covert extortion.
Timeline of the Hack: From 4,000 BTC Lost to Blockchain Negotiations
The incident began on Sunday, 6 September 2026, when Liquid Network announced on X that approximately 4,000 BTC had been withdrawn from the federation wallet that backs L‑BTC tokens.
Bitcoin.com News reported that the wallet previously held around 4,200 BTC, meaning the attacker drained nearly 95% of the total funds, leaving the federation wallet with only about 4.7% of its intended backing.
Technical analysis from Cryptobriefing and Bitquery revealed the cause: an inflation bug in Elements, the open‑source codebase that powers Liquid. The bug allowed the attacker to mint more than 4,000 L‑BTC without real backing, then cash them out into real BTC through SideSwap's peg‑out mechanism.
Read Also: MEDS Mask Stock: Getting to Know the Business of the Medical Device Issuer and Its Products
Because the transactions appeared valid under the flawed consensus rules, the federation's security system signed them like any normal transaction — Liquid itself stressed that the Peg‑out Authorization Key (PAK) was not directly hacked; the vulnerability lay in the consensus logic.
Once the incident was revealed, Liquid immediately disabled the bridge nodes and asked all exchanges to temporarily halt L‑BTC deposits and withdrawals. On the bright side, other assets on the Liquid network, such as USDT and DePix (a Brazilian stablecoin), were reported to be unaffected because the vulnerability was specific to the L‑BTC peg‑out mechanism.
If you want to keep trading Bitcoin with peace of mind amid security incidents like this, make sure you trade on a transparent and properly licensed platform like Bittime.

The Evidence Behind the Claim of 3,400 BTC Returned
This is the part that often gets overlooked in fast‑paced news: the negotiation process between Blockstream and the perpetrator actually took place openly, entirely through messages embedded in Bitcoin transactions (OP_RETURN) — not through private channels that could not be publicly verified.
The perpetrator, who called themselves a "white hat hacker," left an on‑chain message asking Blockstream to patch all bridge nodes before the funds would be returned.
Blockstream responded via PGP‑signed messages on the same channel, and the signature matched the company's publicly published security keys. On 7 September, Blockstream confirmed that the bridge nodes had been patched and stated that it was safe for the funds to be returned.
Read Also: BIS Reveals New Potential of XRP Ledger for Digital Financial Systems
One day later, crypto.news and KuCoin News reported that the perpetrator did indeed return 3,400 BTC worth approximately $268–269 million to the federation wallet — this transaction can be directly traced on a block explorer, so it is not just a claim made on social media.
However, about 600 BTC (~15% of the total, worth roughly $47 million) remains in the perpetrator's address as of the time of this writing.
Interestingly, not all media reported this detail consistently. Some early articles even described the entire incident as "unconfirmed" without verifying the transaction hashes that were already publicly traceable — illustrating how the fast‑paced crypto news cycle can sometimes leave important details behind or cause confusion along the way.
Controversy: Is This Really a White Hat Act or Covert Extortion?
The "white hat" label the perpetrator gave themselves became a subject of heated debate among industry players once part of the funds was returned.
Ledger CTO Charles Guillemet wrote on X that holding 600 BTC without a publicly announced bounty agreement looked more like extortion than ethical security research.
He compared this pattern to the Ronin Bridge hack and the Euler Finance hacker's negotiations, where large funds were taken first, only to be followed by a claim of good intentions later.
Read Also: 10 Free Bitcoin Mining Sites and Faucets 2026 – Which Ones Are Legit?
Samson Mow, former Chief Strategy Officer at Blockstream, added further complexity by claiming that a contact request via Signal that circulated did not come from the address that actually held the stolen funds — suggesting potential identity confusion amid the highly public negotiation process.
For comparison, a similar case occurred with the Verus Protocol Ethereum bridge exploit in May 2026. The attacker at that time returned 75% of the funds and kept 1,350 ETH (~$2.8 million), but that happened after Verus publicly announced the settlement terms to the public.
The Liquid case is different because, to this day, Blockstream has never stated that the remaining 600 BTC is an officially approved bounty — so its legal and ethical status remains up in the air.
Read Also: 10 Free Bitcoin Mining Sites and Faucets 2026 – Which Ones Are Legit?
Conclusion
The claim of the return of 3,400 BTC on Liquid Network actually has fairly solid on‑chain evidence — from Blockstream's PGP‑signed messages to transactions that can be directly traced on a block explorer.
What remains a question mark is not whether the return actually happened, but the status of the perpetrator as a true "white hat" and the fate of the 600 BTC still being held without any official agreement. This incident serves as an important reminder that blockchain transparency can prove a transaction occurred, but it does not automatically answer the ethical questions behind it.
Check the prices of Bitcoin (BTC), Ethereum (ETH), XRP, Solana (SOL), GRAM, and BNB, as well as top memecoins like DOGE. You can trade directly on Bittime!
Bittime is a licensed Digital Financial Asset Trader (PAKD) platform, registered and supervised by the Indonesian Financial Services Authority — where you can buy Bitcoin in Indonesia and hundreds of other crypto assets starting from Rp10,000. Registration is quick, secure, and you can start today.
Monitor the USDT to IDR conversion rate and real‑time price movements of your favourite crypto assets. All available in one crypto investment app available for free download on the Play Store.
Ready to start? Sign up now on Bittime and execute your investment strategy on a platform trusted by millions of users in Indonesia.
FAQ
Has the return of 3,400 BTC on Liquid Network been verified?
Yes, the return transaction can be directly traced on a block explorer and was confirmed via PGP‑signed messages from Blockstream, not just a social media claim.
Why are 600 BTC still not returned?
To date, Blockstream has not published an official bounty agreement regarding the remaining funds, so its status remains unresolved.
What was the main cause of the Liquid Network hack?
The cause was an inflation bug in the Elements code that allowed L‑BTC tokens to be minted without actual BTC backing.
Did this incident affect the price of Bitcoin?
Bitcoin price was relatively unaffected and held around $80,000, because the security flaw was specific to the Liquid sidechain, not the Bitcoin core protocol.
Is the perpetrator really a "white hat hacker"?
This status is still debated; several industry figures, including Ledger's CTO, believe that holding part of the funds without an open agreement resembles extortion more than ethical security research.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.



