
Blockstream announced that it had completed a patch for the bridge node after an entity that withdrew approximately 4,000 BTC from the Liquid Network and identified itself as a white hat made the vulnerability fix a condition for returning the funds.
Through a Bitcoin OP_RETURN message, the entity said, “First fix the bug and make sure all nodes have been patched,” adding that it would safely return the funds once the fix was confirmed. It also encrypted and sent details related to the vulnerability to Blockstream.
Blockstream later responded in a PGP-signed on-chain message: “The bridge node has been patched, and it is safe to return the funds.” The negotiation between the two sides proceeded publicly through OP_RETURN messages.
Earlier, approximately 4,000 BTC—worth about $320 million at the time—was withdrawn from the Liquid Federation wallet. The attacker expressed an intention to return most of the funds, and as of the time of reporting, approximately 4,000 BTC remained in the attacker’s wallet.
Sources
- The Block — Liquid Network attacker says they will return most of 4,000 BTC after bug fix — 2026-09-07
- Bitcoin.com News — Blockstream to Liquid Network Hacker: ‘Safe to Return the Funds’ — 2026-09-07
