The stolen amount represented roughly 95% of Liquid’s reserves, which stood at about 4,200 BTC. That temporarily left L-BTC holders unable to redeem their tokens for the Bitcoin meant to back them, turning what might sound like an abstract software flaw into a direct solvency and redemption problem.
TRM Labs classified the incident as the largest cryptocurrency theft of 2026 so far. Some initial reports valued the withdrawal at approximately $340 million, although several later accounts placed it closer to $320 million based on Bitcoin’s price at the time.
Why is the attacker being called a white hat?
The attacker opened communications through a blockchain message reading: “we are whitehats. contact us on chain.” Blockstream later replied through the same channel: “Bridge nodes are patched, safe to return the funds.”
On September 7, former Blockstream executive Samson Mow said the vulnerability had been fixed and about 3,400 BTC had been returned. The Block, TechCrunch and The Hacker News separately corroborated that repayment through the on-chain messages and transactions.
What remains unclear is whether anyone authorized the attacker to keep the balance as a reward. Neither Liquid nor Blockstream had publicly confirmed such an agreement by September 9, according to The Hacker News. Decrypt reported that Blockstream was still negotiating to recover the outstanding Bitcoin.
Ledger chief technology officer Charles Guillemet rejected the friendly label outright. “The ‘white hats’ still hold 600 BTC,” he wrote, arguing that any undisclosed arrangement allowing the attacker to retain the money would look more like extortion than responsible security research.
That distinction matters. White-hat researchers usually seek permission, disclose flaws responsibly or negotiate a documented bounty. Removing nearly an entire reserve and deciding afterward how much to return rather stretches the job description.
When will Liquid Network fully restart?
Liquid paused operations while Blockstream investigated the breach and prepared security changes. The Hacker News reported that updated software had been deployed and federation members were preparing a coordinated restart.
Still, no outlet had confirmed a complete restart by September 9. Liquid’s status page continued to show an active bridge outage on September 8, and there was no verified return of the remaining 598.5 BTC.
Before reopening the affected systems, Blockstream and Liquid were expected to introduce further fixes and security improvements. The immediate software vulnerability may be closed, but the incident also exposed the danger of concentrating nearly all backing reserves behind a bridge that can be drained through one upstream flaw.
For users, the important question is not simply whether the network resumes producing transactions. It is whether redemptions can proceed normally, reserves remain adequate and the outstanding Bitcoin is recovered. A green status indicator would be welcome, but it would not make $47 million reappear.
How does the theft compare with other 2026 attacks?
The Liquid breach is part of a particularly expensive run of cryptocurrency security failures, though its partial reversal makes it unusual.
A Coldcard hardware wallet attack initially drew attention after thieves took 594 BTC from about 500 wallets in just 25 minutes by exploiting a flaw affecting certain Mk3 devices. Later reporting showed the campaign was much larger. Fortune documented four theft waves affecting more than 5,200 addresses, while Self Custody Labs counted about 1,816 BTC, worth roughly $116 million, stolen between July 30 and August 4.
Another theft followed a mistake by South Korean authorities. Officials seized nearly $5 million in cryptocurrency from a suspected money launderer, then exposed the wallet’s recovery phrase in evidence photographs. Someone used the phrase to remove about $4.8 million. Digital assets are secure, provided nobody publishes the password.
Liquid’s attacker at least returned the majority of the funds. The unresolved 598.5 BTC now determines whether the episode is remembered as an aggressive vulnerability disclosure, a negotiated bounty or a very large theft followed by a substantial partial refund.