Industry News

Hackers Behind $320M Liquid Network Withdrawal Signal Willingness to Return Funds

UToday · 7 Sept 2026
Key Takeaway Businesses using or holding assets on blockchain bridges should treat large custodial pauses as a signal to review third-party exposure and wait for verified official updates before assuming funds are safe.

An unidentified group that withdrew roughly 4,000 BTC (about $320 million) from Blockstream's Liquid Federation wallet, accounting for around 95% of the Bitcoin pegged into the sidechain, is now negotiating a partial return of the funds. The incident began on Sunday, prompting Liquid to disable its bridge nodes and pause the network. The attackers consolidated the funds into a single address with a message identifying themselves as 'whitehats' and inviting contact.

According to Galaxy Research's Alex Thorn, Blockstream and the actors have since exchanged verified PGP-signed messages via Bitcoin OP_RETURN transactions. The attackers indicated they would return 'most' of the funds, but only after the underlying vulnerability that allowed the withdrawal is fixed. It remains unclear how much Bitcoin they intend to keep, and there is no guarantee the pledge will be honoured.

Security commentators have been divided on the actors' intentions. Ledger's CTO Charles Guillemet initially compared the incident to malicious bridge exploits like Ronin and Euler, but later softened his stance after the attackers engaged in direct communication, a behaviour unusual for criminal groups.

Summarised by CISO AI from UToday. We link back to every original so you can read it yourself.