The Liquid Attackers Gave Back 3,400 Bitcoin and Kept $47 Million. Nobody Agreed to That.
The Liquid hack funds returned amount to 3,400 BTC of roughly 4,000 taken, leaving 598.5 BTC — about $47 million — retained by attackers as a self-declared bounty.
On this page
- What was actually agreed
- The numbers
- Why the framing matters more than the money
- What is still unresolved
- The precedent problem in numbers
- What to watch
- What a defender can actually do next time
On 6 September attackers drained roughly 4,000 BTC — about $319 million — from the Liquid Network. On 7 September they returned 3,400 BTC, worth around $272 million.
They kept 598.5 BTC, approximately $47 million, and describe it as a bounty.
What was actually agreed
Nothing, in the ordinary sense of the word.
The attackers embedded an on-chain message reading "we are whitehats. contact us on chain," then negotiated through encrypted Bitcoin transactions. They said they would return the funds once Blockstream patched the vulnerability. Blockstream confirmed the bridge nodes were patched and that funds were safe to return.
The 85% came back. The 15% did not, and the characterisation of that remainder as a bounty is the attackers' own. It has not been verified, and there is no public evidence that Blockstream offered a bounty of that size or of any size.
That distinction matters. A bounty is something a defender offers before or during a disclosure. What happened here is that someone took $319 million, gave most of it back, and unilaterally set their own fee.
The numbers
| Amount | Value | |
|---|---|---|
| Drained, 6 September | ~4,000 BTC | ~$319m |
| Returned, 7 September | 3,400 BTC | ~$272m |
| Retained | 598.5 BTC | ~$47m |
| Recovery rate | 85% | — |
An 85% recovery is far above what the sector normally achieves. For comparison, roughly $110.7 million of August's $215 million in total losses was frozen or returned, and that figure was itself unusually high because a chain halt stopped funds from moving.
Why the framing matters more than the money
One reading of this is a good outcome. A serious vulnerability was found, exploited, disclosed and patched, and most of the money came back. Users are largely whole.
A second reading is that a norm has just been established: take everything, return most of it, keep a percentage, and call the percentage a bounty. If that works once at $47 million, it will be attempted again.
The distinction between a security researcher and a thief has historically been consent. A researcher who finds a flaw discloses it and receives whatever the programme offers, typically 5% to 10% capped at a negotiated maximum. Someone who takes the funds first has removed the defender's ability to decline.
Blockstream's position is genuinely difficult. Refusing to engage risks losing all of it. Engaging validates the method.
What is still unresolved
The network is paused. Liquid remains offline and exchanges have not resumed L-BTC trading.
The $47 million. No public agreement covers it, and no mechanism exists to compel its return.
Whether users are made whole. With 598.5 BTC missing against reserves that normally hold about 4,200 BTC, a shortfall of roughly 14% remains unless Blockstream or federation members cover it. Nothing has been announced.
Attribution. The attackers' identity and location are unknown. If they turn out to be in a sanctioned jurisdiction, the negotiation itself creates legal exposure for anyone who engaged with it.
The precedent problem in numbers
DeFi protocols lost at least $1.3 billion in the first eight months of 2026, and North Korea's Lazarus Group accounts for roughly 44% of that. Those attackers do not negotiate and do not return funds.
Against that background, an attacker who returns 85% looks almost cooperative. That comparison is exactly how a bad norm becomes acceptable — not by anyone endorsing it, but by it looking reasonable next to something worse.
What to watch
Whether the $47 million moves. On-chain, and visible. Movement toward mixers or exchanges would resolve the white-hat question immediately.
Whether Blockstream publishes the negotiation. Full disclosure of what was and was not agreed would settle the bounty framing.
When L-BTC trading resumes, and at what price. Any discount to bitcoin is the market's estimate of the remaining shortfall.
Whether other protocols see the same approach. This is the number to watch over the next quarter, and it is the real cost of how this ended.
What a defender can actually do next time
The uncomfortable truth is that Blockstream's options were set long before the negotiation started.
Once an attacker holds the funds, the defender is choosing between a bad outcome and a worse one, and no amount of negotiating skill changes that. The decisions that mattered were made months earlier: the size of the bug bounty programme, whether the range proof caching code had independent review, and whether anything monitored for anomalous issuance.
A 36-minute window between minting unbacked tokens and a federation payout is a monitoring gap, not a negotiation failure.
The protocols reading this incident should be auditing that gap rather than drafting negotiation playbooks. The playbook only gets used on the day you have already lost.
About this report. Amounts, dates, the on-chain message and the negotiation sequence are from TRM Labs' analysis and reporting by The Hacker News, Crypto Briefing and crypto.news, 7-9 September 2026. The bounty characterisation is the attackers' own and is unverified. Comparative 2026 loss figures are from crypto.news reporting of rekt.news data and CertiK's August report.
Not investment or security advice. Details remain subject to revision as the incident develops.
Sources
- 2026's Biggest Hack To Date: Attackers Drained $319 Million From Liquid Network, Then Returned 85% — TRM Labs
- Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug — The Hacker News
- Blockstream confirms bridge nodes patched, funds safe to return — Crypto Briefing
- Liquid attackers offer to return most of 4,000 BTC — crypto.news
Read next
- A Bitcoin Sidechain Just Lost 95% of Its Reserves. The Federation Multisig Held. The Liquid Network hack drained about 3,996 BTC worth $320m on 6 September, roughly 95% of reserves, through …
- Injective Stopped Producing Blocks for Four Hours to Contain a $4.9 Million Exploit, Then Called It an Upgrade Injective's chain stopped for 3 hours 42 minutes on 31 August during a $4.9m exploit. The foundation calls it…
- $215 Million Gone in August, and One Attack Accounted for More Than Half of It CertiK counted $215m in confirmed crypto losses in August 2026, with $144.6m from DeFi. The Tectonic exploit …