Liquid recovers 3,400 BTC, but its peg-out gap exposes bridge accounting risk

- The actors behind Liquid Network’s roughly 4,000 BTC incident returned 3,400 BTC, about $269.2 million, on Monday after Blockstream signed a message confirming its bridge nodes were patched, but close to 598.5 BTC remains outstanding.
- The case matters to anyone holding bridged Bitcoin because the drained peg-out processed as a valid transaction, exposing weak reserve monitoring rather than any flaw in Bitcoin itself.
- Until the rest is returned or the backing gap is covered, Liquid has not said when its peg services will resume.
The Liquid Network was able to recover a significant portion of the Bitcoin (BTC) taken from its federation wallet over the weekend. However, this does not get rid of the more serious point. The problem of the event is that the peg-out can take place via the expected authorization route even if the L-BTC involved in the transaction should not have been created.
On Monday (September 7), the group responsible for the withdrawal refunded 3,400 BTC to the federation, returning around 85% of the lost money. The transaction left them with 598.5 BTC. For consistency, all dollar conversions in this article use CoinMarketCap’s Bitcoin to USD conversion rate of $79,001.61 (which was indicated on Sept. 7).

A valid peg-out that the federation says it never authorized
At first glance, the transaction seems routine. SideSwap claimed that at 14:05 UTC on Sunday, a customer transmitted 4,000 L-BTC to its peg-out service. After presenting a valid SideSwap peg-out authorization, roughly 3,996 BTC was made available from the federation’s wallet at 14:28:56 UTC.
However, the authorization key was not stolen. Liquid reported that SideSwap’s authorization key was not used improperly. SideSwap also reported that Blockstream later determined that the reason for the event was a failure in Elements software, which enabled the generation of invalid L-BTC. Hence, the peg-out mechanism was allowing incorrect tokens to slip through, which appeared to be legitimate, even though they didn’t have the backing that L-BTC was supposed to have.
This makes the matter different from usual cases of key compromise and moves it into the domain of accounting problems. According to Liquid’s whitepaper, L-BTC is defined as Bitcoin that enters the sidechain with the help of a so-called two-way peg, where some BTC in the hands of a federation is used to redeem the coin. And if L-BTC is entered in an invalid way through its redemption path, the importance of the reserves’ integrity equals the importance of the authorization keys themselves.
The negotiation played out in Bitcoin transaction messages
The communication between Blockstream and the actors occurred through messages that were embedded in the Bitcoin transactions. The timeline of Samson Mow indicated that the actors were urging Blockstream to fix the vulnerability before they would return the money.
Later on, Blockstream sent out a signed note saying, “Bridge nodes are patched, safe to return the funds.” The actors confirmed with Blockstream the final destination and returned the money amounting to 3,400 BTC back to the Liquid Federation at 16:09:25 UTC on September 7.
Why the missing 598.5 BTC keeps the reserve question open
Getting back 85% of the funds is certainly a big win, but it doesn’t fix the problems for a system that relies on one-to-one backing. Approximately 598.5 BTC remains outside of the federation, representing about $47.3 million at the market price calculated in this case.
According to a previous report by Cryptopolitan, a peculiar aspect of the event was that it used the SideSwap peg-out authorization mechanism, although no breach occurred at the key level. The Bitcoin base layer was functioning properly as well. The problem lay upstream where falsely minted L-BTC was going through a redemption mechanism aimed at releasing real BTC.
What the users of bridged Bitcoin should take away from this event is this: this was more than just a theft of a private key. It showed how a software problem can lead to a legitimate-seeming redemption request being made without actual reserves to back it. Even if the remaining bitcoin are returned back, the underlying issue remains: Liquid’s peg-out process manages to convert actual BTC to L-BTC that never should have been considered validly collateralized.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
How much did the Liquid hackers return, and how much is still missing?
The actors returned 3,400 BTC, worth around $269.2 million, or about 85% of the funds, according to Decrypt. Roughly 598.5 BTC, about $47 million, remains in the address linked to the withdrawal.
What made the hackers send the Bitcoin back?
The return followed a PGP-signed message from Blockstream stating that Liquid's bridge nodes had been patched and it was safe to return the funds, per Samson Mow's on-chain timeline.
Was Bitcoin itself hacked in the Liquid incident?
No. SideSwap said the 4,000 L-BTC was burned against a valid peg-out authorization before the federation released the Bitcoin, and Cryptopolitan has previously reported the issue involved SideSwap's peg-out authorization key rather than any compromise of Bitcoin's base layer.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ibiam Wayas
Ibiam Wayas has covered the crypto news beat since 2019. He studied Computer Science at National Open University of Nigeria. His work has appeared on various crypto news platforms, including Coinfomania, Crypto News Australia, and AltcoinBuzz. Drawing on his background in Computer Science, he now focuses on crypto, robotics, and longevity news.
















