September 8, 2026
Over the weekend, attackers exploited a vulnerability in Liquid, the Bitcoin sidechain operated by Blockstream, and moved close to 4,000 BTC (around $320 million at the time) out of the network. By Monday, most of it was back: 3,400 BTC, about 85 percent of what was taken. The remaining roughly 598 BTC, worth about $47 million at the time, is staying with the attackers, who framed it as a bounty for the vulnerability they found.
What was taken and how
Liquid is a federated Bitcoin sidechain launched by Blockstream in 2018: BTC gets locked on the Bitcoin mainchain and an equivalent amount of L-BTC is minted on Liquid, redeemable back through a peg controlled by a federation of 15 companies. Moving funds across that peg normally requires signatures from 11 of the 15 members. The attackers found a flaw in the bridge that let them route funds to a new address without going through that approval process, draining close to 95 percent of the network’s Bitcoin reserve. Blockstream shut down the bridge and asked exchanges to freeze pending L-BTC deposits and withdrawals while it investigated.
A negotiation conducted entirely on-chain
What stands out is not the theft itself, sidechain bridges get exploited with some regularity, but how the aftermath played out. The attackers left a message for Blockstream embedded in a public Bitcoin transaction: they would return most of the funds once the vulnerability was patched and every node updated, and they would keep a portion as compensation for exposing the flaw. Once the fix was in place, Blockstream’s response was also a signed message on Bitcoin, confirming the network was safe and that it was fine to send the funds back. On Monday, at block 965,950, the 3,400 BTC moved back into the network.
No emails, no ransom note, no back channel through a security firm: the whole exchange happened as messages attached to transactions on the same ledger the dispute was about.
What I find notable
The amount kept, about 598 BTC, was not agreed with Blockstream. The attackers set it themselves and called it a bounty, and Blockstream’s only real leverage was patching the bug and asking nicely. There was no bug bounty program pricing this in advance, no back and forth over the number: an exploit turned into a unilateral invoice. It is a similar pattern to the Poly Network hack in 2021, where an attacker who took around $600 million returned nearly all of it and was later offered a security role by the project. It is starting to look like a recognizable playbook: exploit a bridge, negotiate through the chain itself, keep a self-assessed cut, and let “returned most of it” stand in for accountability.
It also says something about how much trust these systems still depend on. A network that requires 11 of 15 companies to agree before moving funds is not trustless, it is a smaller, semi-formal version of the same trust relationships that back a bank. The difference here is that the vulnerability disclosure process ran through the attacker instead of a security researcher, and the price of that disclosure was whatever the attacker decided to charge.
Sources: