Liquid Network has recovered 3,400 BTC following a suspicious withdrawal, but nearly 600 BTC remains connected to the incident, while L-BTC peg services continue to be suspended with no reopening date announced.
In the latest Bitcoin news, the individuals who withdrew roughly 4,000 BTC from the Liquid Network have returned 3,400 BTC, worth around $269.2 million, to the network’s federation wallet. The recovery accounts for about 85% of the Bitcoin involved in the incident.
However, approximately 598.5 BTC, valued at close to $47 million, remains in an address associated with the withdrawal. Liquid has not provided details on whether those funds will be recovered or explained how it would address any potential deficit in L-BTC backing.
Although most of the Bitcoin has been recovered, the incident is far from fully resolved. Questions remain about the status of the remaining coins, the security of Liquid’s reserves and when its normal services will be restored.
The 598.5 BTC still sits at an address linked to the incident rather than one officially identified as a lost-funds wallet. Liquid has not confirmed whether the Bitcoin will eventually be returned, how any reserve shortfall would be managed, or when its sidechain and peg operations will restart.
How the Liquid Bitcoin Incident Unfolded
The incident started Sunday when a user sent 4,000 L-BTC to SideSwap’s peg-out service. The transaction resulted in an unusual withdrawal from Liquid’s federation reserves.
Liquid subsequently shut down its bridge nodes and asked exchanges to halt L-BTC deposits and withdrawals while its team investigated the situation. The emergency measures were intended to prevent additional losses while the network assessed the security breach.
The parties responsible later identified themselves as white-hat hackers through a message recorded on the Bitcoin blockchain. They claimed the network remained vulnerable until its nodes had been patched.
Communication between the attackers and Blockstream, Liquid’s developer, continued through Bitcoin transactions. The exchange eventually resulted in Blockstream signing a message confirming that the affected bridge nodes had been patched and were secure.
The attackers then sent 3,400 BTC back to Liquid’s Federation address. They had previously indicated that they would return most of the funds, but did not explain why roughly 600 BTC would remain under their control.
The incident has renewed concerns over the security of Bitcoin sidechains and their supporting infrastructure. Liquid relies on a federation wallet and bridge nodes to manage its sidechain, both of which were taken offline after the abnormal withdrawal was discovered.
For now, L-BTC deposits and withdrawals remain frozen. Liquid has not provided a timetable for bringing the services back online, leaving users unable to move assets through the network’s peg.
Ledger Chief Technology Officer Charles Guillemet has also challenged the attackers’ white-hat label. After most of the Bitcoin was returned, Guillemet argued that keeping around 600 BTC did not resemble a conventional bug-bounty arrangement and was more consistent with extortion.
His comments highlight a broader issue in the crypto industry: how should funds be classified when hackers return most, but not all, of the assets taken during an exploit?
Liquid has yet to confirm the fate of the remaining 598.5 BTC, explain how any L-BTC backing gap would be handled, or announce when its sidechain and peg services will return to normal.































