Hackers Return $266 Million to Liquid Network, Keep $47 Million as 'Bug Bounty' After Public Negotiation
A high-stakes, public negotiation between alleged 'white-hat' hackers and cryptocurrency trading platform **Liquid Network** concluded with the return of $266.5 million in stolen Bitcoin. The attackers, who initially siphoned off $320 million, retained $47 million as a self-proclaimed reward for identifying a critical vulnerability in the platform's underlying **Elements** software.
On Sunday, **Liquid Network**, a trading platform operated by **Blockstream**, announced that "purported white-hat hackers" had withdrawn 4,000 **BTC** (valued at approximately $320 million at the time) from its wallet. The company swiftly paused deposits and withdrawals and initiated contact with the attackers.
### Public Blockchain Negotiations Unfold
The hackers, who identified themselves as "whitehats" in a message attached to the transaction, engaged in a public, hours-long negotiation on the blockchain. Their initial message, bridging the $320 million out of **Liquid**'s account, stated: "we are whitehats, contact us on chain."
Subsequent messages from the attackers indicated their intent to return most of the funds, contingent on **Blockstream** addressing an alleged vulnerability. "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix," they demanded.
### A $47 Million 'Reward' Secured
After a series of public and private exchanges, the hacker sent $266.5 million worth of **Bitcoin** back to **Liquid** on Monday morning. They retained 598.5 **BTC**, equivalent to about $47 million, as a self-determined reward for their efforts.
**Blockstream** subsequently confirmed the negotiations and announced the deployment of "updated software" as they prepared to restart the system.
### Vulnerability Traced to Elements Software
The incident ignited widespread debate within the cryptocurrency community regarding the source of the vulnerability. While **Blockstream** and **Liquid** have not yet responded to requests for comment, a post-mortem published by **SideSwap**, the service used by the hacker to move the funds, suggested the issue stemmed from a vulnerability in the **Elements** software.
Several blockchain security experts, including **CertiK**, have also independently traced the root cause back to **Elements**. Founded in 2015, **Elements** allows users to create blockchains extending from **Bitcoin**'s codebase, with **Blockstream**'s **Liquid** being a prominent example of an **Elements**-based sidechain in production.
**Liquid**, launched in 2018 and backed by major cryptocurrency players, aims to facilitate faster **Bitcoin** transactions and extend **Bitcoin**'s use cases into new capital markets.
### One of the Largest Crypto Thefts of 2026
The initial $320 million theft marks one of the largest cryptocurrency incidents in 2026. This follows two April incidents where alleged North Korean hackers reportedly stole $290 million and $280 million from the **Kelp** and **Drift** platforms, respectively.