The “White hat” party that withdrew nearly 4,000 bitcoin from the Liquid Network federation wallet on Sunday returned 3,400 BTC to the wallet on Monday. About 598 BTC, or 15% of the consolidated pile, stayed at the same holder address as an implied bounty fee worth 48 million dollars.
The return transaction (bc49a46d), confirmed at 16:09 UTC on September 7. It returned exactly 3,400 BTC to the labeled Liquid peg script address and sent the 598.5 BTC change back to the “White hat” hacker address as change.
The transfer followed a day of messages written into Bitcoin blocks. The White hats first published transaction on chain with a message in the OP_RETURN arbitrary data field “contact us on chain”; the message came from the address holding the 4000 BTC taken from the Liquid Network.
A Blockstream-linked address answered with “Please contact [email protected]”. Later notes from that sender carried Electrum-encrypted payloads and PGP signatures that can be verified against Blockstream’s published security key.
In block 965869, the White hats asked in the clear text whether sending “most” back to the federation script was acceptable. The 1,000-sat output on that transaction was only a message carrier.
Soon after, the White hats wrote “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” followed by an encrypted blurb of text to Blockstream’s PGP key.
In the same block, a clear-signed reply from the Blockstream sender said “Yes, thank you.” Hours later, the same Blockstream posted another clear-text note: “Bridge nodes are patched, safe to return the funds”.
Minutes after the 3,400 BTC landed. The white hats sent back 85% of the funds, keeping 15% as an implied finder’s fee. The choice was celebrated by some on X as ‘better than keeping 100%’ while others were a bit shocked at the amount. While 15% might sound reasonable, the total sum is so large that it nears $50 million at today’s prices. Blockstream was clearly not happy about the finder’s fee, as four encrypted messages followed onchain a few hours later, likely after the main fires had been put out at the office and the lawyers had a chance to have a say in the matter. An hour later, one more encrypted message was posted from Blockstream.
The White hats replied with two encrypted messages. Blockstream replied once an hour later. Then the White hats published a simple yet meaningful “ 🙁 ” sad face emoji. This emoji does a lot of work. It suggests that negotiations did not go well over reducing the size of the bounty. Blockstream wizards are clearly ‘big mad’ about the size of that finder’s fee. What exactly was said in those encrypted messages is not known and Blockstream has made no public statements on the matter. But we can only assume the saga is not over.
The full chat can be easily followed on this vibe-coded site (by yours truly). A couple of other researchers are keeping tabs on the conversation and on-chain data, such as Sjors’s GitHub gist and Alex Thorn from Galaxy Research.
Liquid’s Sunday statement is still the network’s last official account post: purported whitehats withdrew about 4,000 BTC through the SideSwap peg-out path, the PAK itself was not compromised, other issued assets were unaffected, and the sidechain was paused. Liquid and Blockstream had not posted a new statement on the 3,400 BTC return as of this writing. SideSwap had said the L-BTC in the original peg-out “came from an Elements bug.”
Facts Only
* The “White hat” party withdrew approximately 4,000 BTC from the Liquid Network federation wallet on Sunday.
* 3,400 BTC was returned to the labeled Liquid peg script address on Monday.
* 598.5 BTC remained at the same holder address as an implied bounty fee valued at $48 million.
* The return transaction used the hash bc49a46d.
* The initial communication involved publishing a message in the OPRETURN field stating "contact us on chain."
* A Blockstream-linked address responded with an email address, followed by Electrum-encrypted payloads and PGP signatures.
* The White hats requested a fix before transferring funds back.
* Blockstream confirmed that bridge nodes were patched, allowing the return of funds.
* The White hats returned 85% of the funds while keeping 15% as an implied finder’s fee.
* Subsequent encrypted messages and an emoji indicated dissatisfaction with the size of the finder's fee.
* Liquid's statement noted that the SideSwap L-BTC peg-out came from an "Elements bug."
Executive Summary
A group referred to as the “White hats” withdrew approximately 4,000 Bitcoin from the Liquid Network federation wallet and returned 3,400 BTC on Monday. A portion of the withdrawn amount, 598 BTC, remained at the original holder address, associated with an implied bounty fee of $48 million. The return transaction confirmed the transfer of 3,400 BTC to a specific address while sending the remaining 598.5 BTC back as change.
The process involved communication across the Bitcoin blockchain where initial contact was made via an OPRETURN message. Subsequent exchanges included messages with Electrum-encrypted payloads and PGP signatures, facilitating coordination regarding a bug fix and fund return. A sequence of on-chain communications involving encrypted replies and emojis suggests negotiation difficulties between the involved parties concerning the finder’s fee, which approached $50 million in value at the time. Liquid and Blockstream did not issue a joint statement regarding the 3,400 BTC return, though prior context indicated the initial peg-out was related to an "Elements bug."
Full Take
The narrative describes a complex, high-stakes negotiation occurring in the semi-public space of the Bitcoin blockchain, involving large cryptocurrency movements and private, encrypted communications. The central dynamic revolves around an external exploit (the "bug") leading to asset withdrawal, subsequent coordination among parties, and a dispute over compensation for handling the fallout. The pattern observed is one where technical security vulnerabilities manifest as financial opportunities, which then trigger a real-world governance conflict regarding asset division. The use of on-chain messages for initial contact, followed by off-chain encrypted negotiation, reflects a tension between transparency (public ledger) and necessary confidentiality (legal or operational sensitivity). The evolution from demands to dissatisfaction, symbolized by the emoji, suggests that purely technical solutions are insufficient; the underlying issue is trust management and value assignment. The silence from Blockstream regarding the final negotiation leaves the outcome open-ended, suggesting that systemic risk concerns (security patches) were prioritized over the financial dispute within the operational timeline. This structure mirrors a pattern where complex technical events become simplified into an adversarial narrative focusing on perceived fairness, which often obscures deeper institutional or liability concerns.
Bridge Questions: What is the specific legal framework governing the status of the finder's fee in this context? How do large-scale on-chain communications balance the need for public transparency with operational security secrets? What external factors beyond the direct negotiation timeline influenced the final disposition of the funds and the subsequent communication silence?
Sentinel — Human
The text functions as a detailed report synthesizing on-chain transactions and associated communication during a complex event, displaying the characteristic flow of deep, fact-based investigative journalism.
