
4,000 BTC left Liquid, and the ransom talks are on the blockchain
About 4,000 BTC left the Liquid Network federation wallet over the weekend, worth roughly $318 million at today's price. The negotiation over sending it back is happening on the Bitcoin blockchain, in public, where anyone can read both sides.
The person holding the coins wrote to Blockstream in an OP_RETURN message at block 965,875: fix the bug first, and make sure every node is patched, then the funds come back. They also used PGP-encrypted text. Blockstream answered with a PGP-signed onchain message of its own.
“Bridge nodes are patched, safe to return the funds.”
— Blockstream, in a PGP-signed onchain message, The Block, 7 September 2026
Quote source: The Block, 7 September 2026
At the time that report was published the coins had not moved. The promise covers most of the 4,000 BTC rather than all of it, which is the part where a white hat becomes a bounty negotiation.
Not a stolen key, a minting bug
This was not a stolen key. Liquid is a sidechain where each L-BTC is supposed to be backed one for one by bitcoin held in a federation wallet, and the extra L-BTC in this incident were created by a bug in the Elements software that Liquid runs on.
Technical analysis of the incident points to a rangeproof cache in confidential transactions. The cache key left out asset and script context, so a proof that had already been verified could be replayed, and a subset of nodes accepted the resulting unbacked L-BTC. Those units were then redeemed for real bitcoin.
That distinction matters more than the size of the number. An exchange losing keys is a custody failure. A pegged asset minting itself out of a validation cache is a failure of the promise the peg is built on, and it is the harder thing to reassure people about afterwards.
The fix was already written
The detail that should travel furthest is about release engineering. The fix for this bug had already been merged into the Elements repository days before the incident. It had not been shipped in a tagged build, so the nodes running production were running the version without it.
Nothing in that sentence is exotic. Every team that ships software has a gap between merged and released, and this one had roughly $318 million standing in it. Bridge nodes are now disabled and exchanges have suspended L-BTC deposits and withdrawals while the network is patched.
What to watch now
The pattern is becoming ordinary. We counted seventeen cases of AI agents breaking into real companies this summer, and last week a shipping contractor leaked the home addresses of hardware wallet buyers. Two of those three stories start with a fix that existed before the incident did.
Watch the wallet rather than the statements. Until the coins move, the most valuable thing this incident has produced is a public record of exactly how the bug worked, written by both sides on a ledger neither of them controls.
Nothing here should be taken as financial advice; treat it as information to consider.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
282AI





