Summary
- Purported white-hat hackers offered to return most of the nearly 4,000 Bitcoin withdrawn during the $320 million Liquid Network security incident.
- Blockstream and hackers used Bitcoin OP_RETURN transactions and encrypted PGP messages to negotiate the potential recovery of funds securely on-chain.
- The hackers demanded a network-wide vulnerability fix before repayment, while uncertainty remains over how much Bitcoin they may retain permanently.
The purported white-hat hackers behind the $320 million Liquid Network incident have offered to return most of the withdrawn Bitcoin (BTC). According to Galaxy Research head Alex Thorn, the unidentified actors communicated their proposal to Blockstream through messages recorded on the Bitcoin blockchain.
Nearly 4,000 BTC was removed from the Liquid Federation wallet, representing approximately 95% of the Bitcoin pegged into the sidechain. Liquid subsequently disabled its bridge nodes and paused network operations while Blockstream investigated the vulnerability responsible for the security breach.
Meanwhile, the actors consolidated approximately $320 million in stolen assets into a Bitcoin address and identified themselves as white-hat hackers. Their accompanying message instructed Blockstream to contact them on-chain, establishing an unusual communication channel between both parties.
Despite that claim, Liquid has carefully described the individuals as “purported” white hats because their intentions remain unverified. Furthermore, the hackers have not disclosed how much Bitcoin they intend to retain when returning “most” of the withdrawn funds. That unclear wording leaves Blockstream without any guarantee that the network will recover the entire amount removed from its federation wallet.
Also Read: Bitcoin Holds $79,000 as Zcash Leads Mixed Crypto Market Trading
Hackers Demand Network-Wide Bug Fix Before Returning the Withdrawn Bitcoin
We're back on X.
— 36Crypto (@36Crypto1) August 21, 2026
Our previous account (36crypto2) is currently unavailable while we continue working through the appeal process. In the meantime, this is our new official account. While you are on this page, please support us by sharing and following.
According to Thorn’s reconstruction, Blockstream initiated contact at Bitcoin block 965,822 through a transaction containing 1,000 satoshis. An attached OP_RETURN message alerted the hackers that Blockstream’s security team was prepared to discuss the incident through encrypted communication.
Another transaction contained encrypted information addressed to the holder’s key alongside a Pretty Good Privacy signature associated with Blockstream. Thorn explained that the signature could be verified using Blockstream’s published public key, supporting the authenticity of the encrypted message.
The hackers responded at block 965,869 by moving their balance and transferring 1,000 satoshis into the federation’s peg wallet. Within the accompanying message, they asked whether returning most of the Bitcoin to that wallet would be acceptable.
However, they instructed Blockstream to repair the underlying vulnerability across the Liquid Network before receiving the proposed repayment. “Please fix the bug first,” their message read, emphasizing that the security weakness remained their primary condition for returning funds.
This demand suggests the actors want confirmation that the vulnerability cannot be exploited again before transferring Bitcoin back to Blockstream. Ledger Chief Technology Officer Charles Guillemet initially questioned whether legitimate security researchers would remove hundreds of millions from a blockchain bridge.
He compared the incident with the Ronin and Euler exploits, which involved attackers gaining control over substantial cryptocurrency holdings. Nevertheless, Guillemet reconsidered his assessment once the actors began communicating directly with Blockstream through verifiable on-chain and encrypted messages.
He argued that criminal groups rarely establish contact with victims, offering some reason for optimism regarding a potential recovery. Guillemet also suggested powerful artificial intelligence systems may have helped researchers identify the vulnerability without following conventional disclosure procedures.
Blockstream must now complete the necessary repairs and confirm that Liquid can resume operations without exposing additional user funds. Almost all the withdrawn Bitcoin remains controlled by the hackers, making their promised repayment central to the network’s recovery prospects. Ultimately, the incident remains unresolved because returning the funds depends entirely on the hackers honoring an agreement carrying no enforceable guarantee.
Also Read: Ripple Pushes RLUSD Supply Beyond $2.35 Billion With Large Treasury Mints
