While the majority of assets have been returned, the Liquid Network crisis is far from over. Following Monday’s recovery of 3,400 BTC out of the 4,000 BTC stolen, Blockstream is still actively negotiating. The company is working to secure the remaining 600 BTC, worth roughly $47 million, which is still in the hacker’s hands.
Liquid confirmed that discussions between Blockstream and the attacker remain ongoing in an effort to recover the rest of the funds. However, developers did not provide a timeline or deadline for concluding the talks, leaving tens of millions of dollars under third-party control.
Exploit via SideSwap
The hack originated from a vulnerability in the Elements software platform. The flaw allowed the attacker to mint unbacked L-BTC tokens, which were subsequently used to drain legitimate reserve BTC from the network.
The swapping and withdrawal of the stolen assets were executed entirely through SideSwap, a Liquid Federation member operating peg-out services. This sequence of transactions caused Liquid’s primary reserves to plummet from 4,205 BTC to just 197 BTC before operations could be halted.
Aside from the Bitcoin losses, other denominated assets such as USDT and various native Liquid tokens remained unaffected by the exploit. The private keys belonging to network operators were also confirmed secure and uncompromised.
Not an Ethical Negotiation
The protracted negotiations quickly drew criticism from security experts. Ledger Chief Technology Officer Charles Guillemet openly questioned the attacker’s intentions, pointing out the anomaly of a self-proclaimed white-hat hacker still clinging to 600 BTC.
Guillemet made his stance clear in a blunt statement: “The white hat is still holding 600 BTC. If this is a legitimate reward negotiation, this looks much more like extortion than white-hat hacking!” His remarks highlight the distinction between standard bug bounty rewards and open extortion.
Awaiting the Final Update
Separately, Blockstream’s technical team has prepared an emergency update that is currently under review. This follows a quick patch for peg-in nodes released earlier on Monday.
Until the update is finalized, full network functionality will not resume normal operations. Once the new software is deployed across the infrastructure, network operators will have the ability to reject invalid peg-out transactions.
For institutions and users relying on Bitcoin layer-2 solutions, the missing tens of millions in funds pose a tangible risk. When massive assets become bargaining chips with open-ended negotiations, decentralized ecosystems face growing pressure to find solutions beyond the negotiating table.
Reported via Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




