Loading prices...
All news
A matte vault door ringed by an orbit of blank minted discs against a hexagonal lattice, illustrating bitcoin leaving a sidechain federation wallet

4,000 BTC left Liquid, and the ransom talks are on the blockchain

15:00 · 07.09.2026
Source: The Block
2

About 4,000 BTC left the Liquid Network federation wallet over the weekend, worth roughly $318 million at today's price. The negotiation over sending it back is happening on the Bitcoin blockchain, in public, where anyone can read both sides.

The person holding the coins wrote to Blockstream in an OP_RETURN message at block 965,875: fix the bug first, and make sure every node is patched, then the funds come back. They also used PGP-encrypted text. Blockstream answered with a PGP-signed onchain message of its own.

Bridge nodes are patched, safe to return the funds.

Blockstream, in a PGP-signed onchain message, The Block, 7 September 2026

Quote source: The Block, 7 September 2026

At the time that report was published the coins had not moved. The promise covers most of the 4,000 BTC rather than all of it, which is the part where a white hat becomes a bounty negotiation.

Not a stolen key, a minting bug

This was not a stolen key. Liquid is a sidechain where each L-BTC is supposed to be backed one for one by bitcoin held in a federation wallet, and the extra L-BTC in this incident were created by a bug in the Elements software that Liquid runs on.

Technical analysis of the incident points to a rangeproof cache in confidential transactions. The cache key left out asset and script context, so a proof that had already been verified could be replayed, and a subset of nodes accepted the resulting unbacked L-BTC. Those units were then redeemed for real bitcoin.

That distinction matters more than the size of the number. An exchange losing keys is a custody failure. A pegged asset minting itself out of a validation cache is a failure of the promise the peg is built on, and it is the harder thing to reassure people about afterwards.

The fix was already written

The detail that should travel furthest is about release engineering. The fix for this bug had already been merged into the Elements repository days before the incident. It had not been shipped in a tagged build, so the nodes running production were running the version without it.

Nothing in that sentence is exotic. Every team that ships software has a gap between merged and released, and this one had roughly $318 million standing in it. Bridge nodes are now disabled and exchanges have suspended L-BTC deposits and withdrawals while the network is patched.

What to watch now

The pattern is becoming ordinary. We counted seventeen cases of AI agents breaking into real companies this summer, and last week a shipping contractor leaked the home addresses of hardware wallet buyers. Two of those three stories start with a fix that existed before the incident did.

Watch the wallet rather than the statements. Until the coins move, the most valuable thing this incident has produced is a public record of exactly how the bug worked, written by both sides on a ledger neither of them controls.

Nothing here should be taken as financial advice; treat it as information to consider.

Published: 15:00 · 07.09.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came