The strangest hack of the year just got its strangest chapter. Two days after draining roughly $320 million from Blockstream's Liquid Network, the self-described "white-hat" attacker gave most of it back, then quietly kept about $47 million for themselves, a "bounty" that no one ever actually agreed to. It's a fitting end to a heist that was negotiated entirely in public, one Bitcoin transaction at a time.

What happened

On September 6, attackers withdrew about 4,000 BTC ($320M) from the federation wallet backing Liquid, a Bitcoin sidechain. Rather than vanish, they left a message on the Bitcoin blockchain reading "we are whitehats. contact us on chain," kicking off a bizarre public negotiation conducted through on-chain messages and PGP-signed replies from Blockstream.

The deal that emerged was conditional: the hackers said they'd return the funds once Blockstream fixed the underlying bug. After Blockstream posted a clear-text update, "Bridge nodes are patched, safe to return the funds," the group broadcast a transaction sending 3,400 BTC (~$268 million) back to the federation address. That left exactly 598.5 BTC, roughly $47 million, or precisely 15% of the total, sitting in the attacker's wallet.

The $47 million question

Here's the catch: nobody agreed to that 15%. Nothing in the on-chain messages identified the retained amount as a negotiated bounty, the hackers simply kept it and, according to observers tracking the conversation, signed off with a sad-face emoji. Blockstream, notably, has made no public statement confirming any bounty deal, and by several accounts is "big mad" about the size of the self-assigned fee, with a few additional encrypted messages appearing on-chain afterward, suggesting talks may not be fully settled.

This is the gray zone crypto has never resolved. A "white-hat" traditionally finds a bug, secures the funds before a criminal can, and returns them for an agreed reward. But there was no contract here, no agreement, and no guarantee anything would have come back at all had Blockstream responded slowly. As one analysis put it, "white hat" is a label the attacker chose for themselves, not a status anyone granted. Ledger's CTO Charles Guillemet openly questioned the take-first-negotiate-later approach, while allowing the actors might just be inexperienced researchers. Liquid itself has carefully stuck to calling them "purported white-hat hackers."

Why the bug happened (and why it matters)

Crucially, this was not a stolen-keys hack. Liquid confirmed no federation keys were compromised, and SideSwap said its systems weren't breached. The flaw was in the code: independent technical reconstructions point to a range-proof verification cache bug in Elements, the Bitcoin Core fork that Liquid runs on. In plain terms, the system accepted "bitcoin-like tokens that should never have existed", letting the attacker mint L-BTC that wasn't actually backed by real Bitcoin. It's the same theme running through this year's biggest incidents: catastrophic losses coming from flawed code, not stolen keys.

Where things stand

The recovery is substantial, about 85% of the funds are back, an unusually fast and complete resolution for a nine-figure exploit. But Liquid isn't out of the woods. The network remains paused, bridge nodes are disabled, and L-BTC deposits and withdrawals stay halted at exchanges while Blockstream resolves a chain split and works to ensure every L-BTC is fully backed before restarting. With 598.5 BTC still missing, the network sits around 85% backed, meaning that gap has to be closed, by return, by Blockstream absorbing it, or otherwise, before things fully normalize.

And a bigger question hangs over the case: whether that retained $47 million ends up treated as a settled bug bounty or as proceeds of theft. Blockstream hasn't signaled legal action, which would be difficult anyway given the pseudonymous wallet. Whatever the label, the episode is now a template, and a warning, for how the next nine-figure "white-hat" standoff might play out.