Security3 publishers2 min readPublished
Blockstream paused the Liquid bridge after roughly 4,000 BTC left the federation wallet, and the people holding it will send most of it back only once the flaw is fixed, which puts the patch timetable in their hands.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Alex Thorn's reconstruction verifies one side of the conversation. The PGP signature on Blockstream's message checks against the company's published public key, which is why the outreach can be tied to Blockstream [6]. The other end of the exchange remains unauthenticated. The only established fact about the counterparty is that they control the coins [9]. The reply landed 47 blocks after the outreach [4].
The arithmetic is worth doing before the framing. Roughly 4,000 BTC valued at about $320 million prices the haul near $80,000 a coin [1]. blockchain.news reports that $270 million came back [15], which leaves $50 million outstanding, about 16 percent of what left the wallet [2]. At the $79,324.17 bitcoin price that same publisher quotes, the shortfall is around 630 BTC [3]. That return is single-sourced; the fuller reporting of the exchange has the funds still under the actors' control, with no figure ever attached to "most" [9]. If the $270 million holds, the promise was honored to the letter and the remainder is a fee the federation never agreed to.
The condition is what separates this from a straightforward theft. A demand denominated in a patch still sets a schedule someone else has to meet, and the federation has to write and ship the fix across the network while the counterparty holds the collateral [8]. Publishing it narrows the search area for everyone else reading. Charles Guillemet, Ledger's CTO, made the same point from the other direction when he argued the flaw could be found by pointing powerful AI systems at it, with no disclosure process involved [13].
Ronin and Euler appear in this material only as scale comparators in Guillemet's initial skepticism about the white-hat claim [11], not as negotiation precedents. The evidence backs a single live case, no broader trend line. What it does support is specific: 95 percent of the bitcoin pegged into the sidechain sat in a stranger's wallet [1], and days into the incident Blockstream was still describing itself as working on contacting them [14]. The message in the consolidating transaction [4] shifted the tone of the exchange and shifted Guillemet's read [12], though custody itself never moved. Liquid's own language holds that line by calling the actors purported white-hats [10]. For a responder, the coins are stolen until they are in a federation address, and the patch shipping under this timetable is one the federation did not schedule.
Ranked by verification strength, evidence, and original report placement.
Approximately 4,000 BTC was withdrawn from the Liquid Federation wallet on Sunday, representing about 95% of the bitcoin that had been pegged into the Liquid sidechain.
The incident involved roughly $320 million worth of BTC.
The stolen funds were consolidated into a Bitcoin address containing a message reading: "we are whitehats. contact us on chain."
Following the withdrawals, Liquid disabled its bridge nodes and paused the network.
According to Galaxy Research head Alex Thorn, Blockstream attempted to contact the actors at Bitcoin block 965,822, sending 1,000 satoshis with an OP_RETURN message intended to alert its security team and open a communication channel.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Solid on the drain, single-relay on the deal
The withdrawal is the sturdy part: web3isgoinggreat puts it at 3,998.5 BTC, The Cyber Express at approximately 4,000 and 95% of the peg, blockchain.news at roughly 4,000 in one transaction. Everything past that reaches readers through a single reconstruction by Galaxy Research's Alex Thorn, carried twice in near-identical postings, including the block heights and the PGP signature said to check out against Blockstream's published key. No source publishes an address or transaction ID anyone could verify independently.
Freeze confirmed, return unverified
What can actually be observed is containment: bridge nodes disabled, the sidechain paused, exchanges asked to freeze L-BTC in both directions. On the other side, nothing in this coverage shows bitcoin arriving at the federation address. blockchain.news asserts a $270 million return in a headline and supplies no transaction for it, roughly eleven hours after The Cyber Express reported the coins still sitting with the actors.
Headlines claim a resolution the chain hasn't shown
blockchain.news ran 'Hacker Returns $320M Bitcoin' at 15:45 and 'Hackers Return $270M Bitcoin' four hours later, two incompatible resolutions to a situation whose only documented step is a question asked on-chain about whether returning 'most' would be acceptable. Liquid's own word for the counterparty is still 'purported'. The overstatement lives in the headline furniture rather than in the incident reporting itself.
Exploited issuer, wallet vendor, trading feed
Blockstream is both the victim and the only party who can confirm the encrypted replies are genuine, because verification runs through its own published key. Ledger's CTO is quoted at length on bridge risk while his company sells self-custody hardware, and his revision to 'There's hope' arrives with no new fact attached. blockchain.news wraps each development in Bollinger bands and a death cross, framing that pays whichever way the funds go.
Firm start, open ending
All three publishers agree on the size of the withdrawal, the halt and the taunt left in the address, so the first half is safe to build on. The patch, the amount coming back and the identity of the actors are all still open, and one of the three has already filed two contradictory accounts of the return within four hours.
leadership
Blockstream pauses Liquid after $320 million exploit, tries to reach hackers onchain1 publisher
invest
4,200 BTC walked off Liquid behind an on-chain note claiming white-hat intent9 publishers
invest
Liquid's $320M peg-out ran on an authorization key reported unbreached1 publisher
invest
Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets1 publisher
Publishers with included, body-backed reporting in this cluster.
3 articles · September 7, 2026
2 articles · September 7, 2026
2 articles · September 6, 2026