
AI-generated summary
Liquid Network is a Bitcoin sidechain operated by Blockstream that enables faster and more confidential transactions. It relies on a federation of functionaries to validate transactions and maintain the peg between L-BTC and BTC. The exploit occurred due to a flaw in the Elements software that allowed creation of unbacked L-BTC tokens.
Liquid Network said Tuesday that Blockstream, the Bitcoin infrastructure company behind the sidechain, is in ongoing talks with the hackers who exploited the network for roughly $320 million to fully recover the stolen funds.
“Discussions between Blockstream and the individuals responsible are ongoing to secure the return of the remaining funds,” Liquid said in an incident report on X.
The talks stem from Sunday’s withdrawal of approximately 4,000 BTC, after a flaw in Liquid’s underlying Elements software allowed the creation of unbacked L-BTC tokens that were exchanged for reserve Bitcoin. The hackers returned 3,400 BTC Monday, leaving about 600 BTC, valued at roughly $47 million, outstanding.
Liquid did not say what the terms of the talks were or provide a timeline for recovering the remaining BTC.
According to Liquid, after stealing the tokens, the still-unknown individuals exchanged the BTC through SideSwap, a Liquid Federation member operating a withdrawal service. The software’s transaction checks accepted the unbacked tokens as valid before the withdrawal began.
“Because the validation failure occurred at the transaction level before the peg-out was initiated, both SideSwap’s node and the Liquid Network’s globally distributed functionary nodes accepted the LBTC as valid,” the devs wrote.
Liquid’s reserve fell from approximately 4,205 BTC to 197 BTC after that withdrawal and others processed before operations halted. USDT and other Liquid-issued tokens were unaffected by the vulnerability, according to Liquid, but users could not transact while the network was paused.
“The Liquid Federation functionaries were not hacked, and no private keys were compromised,” Liquid said, attempting to reassure users. “The peg-out mechanism that authorizes withdrawals to whitelisted addresses operated as designed.”
At the time of the exploit, the individuals identified themselves as white-hat security researchers in a message on Bitcoin’s blockchain. Still, some, including Ledger Chief Technology Officer Charles Guillemet, remained skeptical of the actors’ white-hat claim after most of the funds were returned.
“The ‘white hats’ still hold 600 BTC,” Guillemet wrote on X. “If this was ever a negotiated reward under an encrypted contract signed on-chain, it looks more like extortion than white-hat hacking!”
According to Liquid Network devs, Blockstream is preparing an emergency update while the fix undergoes review, following a patch to its bridge nodes on Monday. Once the update is finalized, network operators will make further adjustments to restore operations and correct the network’s state, including rejecting the invalid withdrawal.
“Our immediate priorities are recovering the remaining funds and resuming normal network operations safely and as quickly as possible,” Liquid said.
AI outlook — possibilities, not facts
Liquid Network will resume normal operations after the emergency update is deployed
Likely · Within days
The remaining 600 BTC will be returned through ongoing negotiations
Possible · Within weeks

OpenAI claims its AI solved the Navier-Stokes equations, but NYU mathematician Tristan Buckmaster accuses the company of using his team's unreleased research. OpenAI denies the allegations.

Cronos blockchain developers and validators erased nearly two hours of transaction history to reverse a $111.2 million exploit targeting the Tectonic lending protocol. The move, which invalidated all legitimate transactions during the window, left $9.19 million unrecovered.

Tether's Wallet Development Kit (WDK) provides developers with tools to integrate AI agents into local wallets. The system balances financial autonomy with security by offering configurable transaction policies, session controls, and explicit approval workflows for AI-driven payments.

U.S. law enforcement agencies are raising security concerns over the use of Ray-Ban Meta smart glasses to record inside jails and police facilities. Internal memos warn that the devices could expose sensitive security protocols, leading to new restrictions on eyewear.

A multinational operation led by the U.S. Justice Department disrupted the Sality botnet on Aug. 31. While the action prevents new malware delivery to 33,000+ infected machines, security experts warn that existing local threats, including cryptocurrency theft tools, persist.

The Ethereum Foundation's Protocol cluster has declined EIP-8363 for the Hegotá upgrade, calling for a broader ecosystem process to address validator issuance rewards and holder dilution.