An unidentified trader holding nearly $320 million in drained Bitcoin says the coins will go back only after Liquid Network developers patch the software flaw that made the withdrawal possible. The funds have sat in a single address since Sept. 6, and the sidechain’s bridge remains shut while the two sides negotiate over on-chain messages. The Register first reported the drain.
The withdrawal began as a peg-out request. A customer submitted 4,000 L-BTC, the Bitcoin-backed token used on the Liquid sidechain, to SideSwap’s conversion service. The request passed the standard authorization process, and at least 11 of Liquid’s 15 functionaries signed off. The federation then released about 3,996 BTC onto the main Bitcoin network.
That should not have been possible. SideSwap, working with Blockstream, traced the tokens to a flaw in Elements, the open-source software Liquid runs on. The bug apparently created L-BTC without matching Bitcoin held in reserve, so the federation paid out real coins for unbacked tokens. No signing keys were compromised, both companies said. The L-BTC submitted for conversion looked valid to every signer because the ledger itself recorded it as real.
Liquid disabled its bridge nodes within hours of the withdrawal. SideSwap suspended swaps, peg-ins and peg-outs. Exchanges that support L-BTC paused deposits and withdrawals at the network’s request, leaving the sidechain effectively halted. Traders holding L-BTC cannot move it to main-chain Bitcoin until the bridge reopens.
A negotiation on-chain
The holder has communicated with Blockstream through OP_RETURN messages embedded in Bitcoin transactions. Galaxy Digital’s research head Alex Thorn documented the exchange. Blockstream first asked the holder to contact its security team. The reply came with conditions attached.
The holder said it plans to send “most” of the Bitcoin back to the federation, but only after the bug is fixed and every node on the network is patched.
The message leaves Blockstream with a choice few treasurers ever face: accept terms set by the person holding the reserve, or refuse and risk the coins never coming back. Blockstream has not publicly said whether it accepts the patch-first condition. Liquid’s own statement described the withdrawal as the work of “purported white-hat hackers,” a hedge that reflects how little anyone can verify about the holder’s intent.
Not everyone buys the whitehat framing. Ledger’s chief technology officer rejected it outright, arguing that someone who drains a reserve and then sets terms is an attacker regardless of what follows. The label matters less than the leverage. Once coins reach a regular Bitcoin address, no mechanism exists to compel their return. Past whitehat retrievals happened because the holders chose to give the funds back, not because anyone made them.
The word “most” also does work in that message. It leaves room for a retention, whether framed as a bug bounty or simply kept. Nobody outside the negotiation knows the number. Blockstream has not published a bounty policy for the Elements codebase, so any split would be a first for the project.
What the federation must prove
Recovery alone will not settle the incident. The federation still has to demonstrate that legitimate L-BTC remains backed one-for-one and that the same invalid state cannot pass authorization again. No independent postmortem has been published yet, and the reserve reconciliation is the real test for whether exchanges resume L-BTC flows.
Liquid is a Bitcoin sidechain developed by Blockstream and used by exchanges and financial institutions for faster, more confidential transfers. Its peg depends on a federation of 15 functionaries whose signatures authorize movement of Bitcoin in and out. The model trades decentralized validation for speed and privacy. This incident shows the cost of that trade: a majority of the signature set approved a peg-out backed by nothing, because the data they saw looked legitimate.
The flaw also reaches beyond Liquid. Elements is open source, and other projects run their own federations on the same codebase. Any of them could carry the same bug until a fixed release ships. Operators of those chains now have the same homework Liquid does: audit their peg-outs against the flaw and deploy the patch before someone tests it for them.
The drained wallet held about 4,200 BTC before the incident, so the withdrawal took roughly 95 percent of its holdings. The address now holding the funds showed about 3,998.5 BTC at the latest check. Institutions that park Bitcoin on Liquid face a reserve question until the federation completes its accounting.
Market impact has been limited. Bitcoin traded near $77,000 on Friday, down about 3 percent on the week as spot ETF outflows and rising rate expectations weighed on the broader market. US spot bitcoin ETFs logged three straight sessions of outflows after a $3.8 billion inflow run earlier this month. The Liquid incident still adds to a rough stretch for crypto infrastructure. Within days, an exploit drained more than $100,000 from GoodDollar reserves on Celo, and Router Protocol announced it would shut down and burn 303 million ROUTE tokens after bridge fees collapsed.
For Liquid, the path forward runs through two gates: a patched Elements codebase deployed across every node, and a public accounting showing each outstanding L-BTC token maps to a real Bitcoin in the federation reserve. Until both are done, the largest sidechain experiment in Bitcoin’s ecosystem stays offline, and $320 million of its reserves sits in an address controlled by someone demanding fixes first.
Timing matters too. The incident landed days before a Senate vote on the CLARITY Act, the market-structure bill that would divide crypto oversight between the SEC and CFTC. Critics of delegated-validation designs have already pointed to the Liquid drain as evidence that federation models need harder audit requirements, and the episode gives that argument a concrete example to cite during floor debate.
