Liquid Network’s security crisis changed materially on September 7.
The self-described white-hat actors who had withdrawn nearly 4,000 BTC from the federation wallet returned exactly 3,400 BTC after a series of onchain messages with Blockstream-linked addresses. Roughly 598.5 BTC — worth about $47 million at prevailing prices — remained at the withdrawal-linked address.
That means Liquid recovered roughly 85% of the Bitcoin involved in the incident.
It is a major improvement from the position 24 hours earlier, when almost the entire Bitcoin reserve backing Liquid Bitcoin, or LBTC, had moved beyond the federation’s control.
But the recovery does not close the case.
It creates a new set of questions.
Was the remaining 598.5 BTC an agreed bounty? Was it simply retained unilaterally? What exact vulnerability allowed the original withdrawal? When will Liquid safely restore bridge operations? And what does the episode say about the governance of large white-hat recoveries?
What changed in the past 24 hours?
After the original withdrawal, the actors used Bitcoin transaction messages to describe themselves as white hats and asked Blockstream to communicate onchain.
Blockstream later signaled that bridge nodes had been patched and that the funds could safely be returned.
A subsequent transaction returned 3,400 BTC to the Liquid federation peg address, while approximately 598.5 BTC remained under the actors’ control.
The return is strong evidence that the actors were at least willing to cooperate after the vulnerability was addressed.
It is not, by itself, evidence of a formal bounty agreement.
Some security researchers described the retained amount as a possible bounty. Publicly available information did not establish that Liquid or Blockstream formally agreed to pay a 15% reward.
That distinction matters because $47 million would be an unusually large bounty.
Why the remaining 598.5 BTC matters more than the recovery headline
The first headline is positive:
3,400 BTC came back.
The deeper governance question is:
who decides what a white-hat intervention is worth?
In conventional bug-bounty programs, reward ranges and rules are usually defined before an incident.
The researcher reports a vulnerability, the organization verifies it, and a reward is paid according to the program.
This event happened in the opposite order.
Funds were moved first.
Negotiation followed.
The vulnerability was patched.
Most of the funds were returned.
A large remainder stayed with the actors.
That sequence sits somewhere between a conventional bug bounty and an unauthorized exploit followed by partial restitution.
Crypto needs clearer language for this category.
Why it matters
White-hat recoveries have become an important part of crypto security.
Because transactions are irreversible, a researcher who discovers a critical vulnerability may face a difficult choice.
Reporting it privately can be safer, but the protocol may be actively exploitable by someone else.
Moving funds into a safe address can protect users, but it also means taking control of assets without prior authorization.
The Liquid incident shows why protocols need predefined emergency procedures.
A mature system should establish:
- how researchers can report critical bugs;
- whether emergency fund movement is ever authorized;
- how bounty amounts are determined;
- what proof is required before funds are returned;
- how public communication works;
- what legal protections exist for genuine researchers.
Without those rules, every crisis becomes an improvised negotiation.
The technical problem is still unresolved publicly
The partial recovery should not distract from the original security failure.
Liquid said the withdrawal involved the SideSwap Peg-out Authorization Key mechanism and also said the relevant cryptographic key itself had not been compromised.
Blockstream later said bridge nodes had been patched.
That suggests the vulnerability was related to the way authorization was processed rather than a simple stolen-key incident.
But until a complete technical postmortem is published, that remains an inference.
For users, the important question is whether the patched system now prevents the same class of withdrawal under all relevant conditions.
A bridge should not be considered fully restored simply because funds were returned.
The root cause needs to be understood and independently reviewed.
What the incident says about LBTC backing
Before the recovery, the federation had lost operational control over roughly 95% of its reported Bitcoin reserves.
After 3,400 BTC was returned, most of that backing was again under federation control.
But roughly 598.5 BTC remained outside.
That means users should continue to distinguish between:
economic backing
and
operationally controlled backing.
If a third party holds BTC and intends to return it, the system may eventually be made whole.
But until the federation controls the coins, those assets are not equivalent to ordinary reserves under direct custody.
This is why reserve verification needs to be continuous during bridge incidents.
A 15% bounty would set a powerful precedent
If the remaining 598.5 BTC ultimately becomes an accepted bounty, the precedent will be significant.
A 15% reward on a $320 million incident is far above the normal scale of many structured bug-bounty programs.
Supporters could argue that saving a network from a catastrophic exploit deserves an exceptional reward.
Critics could argue that very large retained amounts create perverse incentives: researchers may be encouraged to move funds first and negotiate later.
The best outcome for the industry is to make large emergency bounties predictable before crises occur.
Protocols managing hundreds of millions of dollars should publish maximum bounty structures that reflect the value at risk.
The difference between recovery and restoration
Recovering funds is only one step.
Restoring a financial network requires more.
Liquid still needs to demonstrate:
- the vulnerability is understood;
- the patch is effective;
- reserve backing is transparent;
- bridge operations are safe;
- exchanges can resume deposits and withdrawals;
- market makers can trust redemption again.
Until then, the network may be financially healthier but operationally impaired.
That distinction is easy to miss.
Risks and counterarguments
It is possible that the 598.5 BTC is part of an agreed arrangement that has not yet been publicly documented.
It is also possible that more funds will be returned.
The actors may have prevented a malicious third party from exploiting the same vulnerability.
If so, the event could ultimately be remembered as a successful white-hat intervention.
But positive intentions do not remove the need for a technical and governance review.
A system holding billions of dollars in potential value cannot depend on improvised negotiations after reserve funds move.
What to watch next
Watch for a full Liquid or Blockstream postmortem, confirmation of the exact bridge-node vulnerability, the status of the 598.5 BTC, any formal bounty agreement, restoration of LBTC deposits and withdrawals, updated reserve attestations, independent code review and changes to federation emergency controls.
The most important lesson has shifted.
Yesterday, the question was whether Liquid could recover its Bitcoin.
Today, the question is whether the network can turn an improvised $320 million security crisis into a repeatable, auditable security model.
FAQ
How much Bitcoin did Liquid recover?
3,400 BTC was returned to the federation wallet on September 7.
How much remains with the self-described white hats?
Approximately 598.5 BTC, worth roughly $47 million at the time of reporting.
Is the 598.5 BTC an official bounty?
Public information has described it as a possible or implied bounty, but a formal 15% bounty agreement had not been clearly established.
Is Liquid fully operational again?
The fund recovery does not automatically mean all bridge and LBTC services are fully restored. Users should verify current operational status before transferring assets.
Has the root cause been published?
Blockstream said bridge nodes were patched, but a complete public technical postmortem remains important.