Liquid Network hackers returned 3,400 BTC, valued at $268 million, on Monday. The actors retained approximately 598.5 BTC, worth $47 million, as the network remains paused.

The return followed an incident that began Sunday, Sept. 6. Roughly 4,000 BTC, then valued at $320 million, left the Liquid Federation wallet backing L-BTC. This drain represented about 95 percent of the network's total reserve, leaving only 197 BTC.

The exploit originated from a range-proof verification cache bug within Elements, a Bitcoin Core fork used by Liquid nodes—not compromised private keys or breached systems at Liquid or Sideswap.

The bug allowed actors to create L-BTC without backing bitcoin. These unbacked L-BTC tokens were then exchanged for real bitcoin from Liquid's reserves. The actors ran a 2.5 BTC dry run before approximately 4,000 L-BTC reached Sideswap's peg-out service at 14:05 UTC. Liquid's federation sent 3,996 BTC to the destination at 14:28 UTC.

The failure centered on L-BTC issuance rather than a compromise of custody keys. Liquid's federation signers operated as designed when presented with a valid withdrawal request.

The actors communicated publicly using Bitcoin OP_RETURN messages, identifying themselves as "whitehats" and inviting contact on-chain. Blockstream responded with PGP-signed messages, and the actors agreed to return the funds after the network was patched.

The "white-hat" designation remains contested. Ledger CTO Charles Guillemet questioned the strategy of taking funds before negotiating their return, though he later suggested the actors might be inexperienced researchers. Liquid cautiously referred to them as "purported white-hat hackers."

On-chain data confirms the actors' address retained 598.49955894 BTC. No on-chain messages identified this roughly 15 percent remainder as an agreed bounty.

The network remains paused, bridge nodes are disabled, and L-BTC deposits and withdrawals at centralized exchanges are halted. Other Liquid-issued assets, including USDT, Depix, and real-world assets, were unaffected by the exploit.