Cut Through CryptoBetaSubscribe
DeFi exploit wave 2026Latest of 26
Liquid Gets 3,400 BTC Back

Liquid Gets 3,400 BTC Back

Verified · 8 Sept 2026BitcoinSep 8, 2026

A relentless wave of DeFi exploits—spanning bridge hacks, oracle manipulation, governance attacks, and AI-accelerated vectors—is draining billions and setting record loss milestones across 2026.

Blockstream confirmed the Liquid Network vulnerability — described in coverage as a validation-cache bug that allowed Liquid Bitcoin to be created out of thin air — has been patched, and the attacker returned 3,400 of the roughly 4,000 BTC withdrawn, per The Block and multiple outlets. About 598.5 BTC (~$47–48 million) was retained as what the parties called a whitehat fee. The funds were returned only after Blockstream signed a message confirming the fix; an inside-job allegation circulating on one YouTube channel was uncorroborated in reporting.

Liquid Recovery: the ransom had a fee attached

Yesterday we gave this story two doors: a whale legitimately holding $320 million of Liquid Bitcoin, or a break-in deep enough to conjure it.

It was the break-in.

A bug in the vault's checking software let the attacker create Liquid Bitcoin from nothing — then trade it in for real coins, by the book.

Now the ending. The bug is patched. 3,400 coins came back.

The people who conjured them kept about 598 — roughly $47 million — and called it a whitehat's fee.

Real security researchers do earn bounties. The convention is around ten percent, agreed with the victim.

This fee was self-set. And the coins came back only after the fix landed — held, until then, as leverage.

That is a ransom's shape wearing a bounty's name.

Here is the part the refund doesn't fix.

The vault's defence is eleven signatures from fifteen operators. That protects against crooked operators — it takes a majority to steal.

But all fifteen machines check withdrawals against the same rulebook. The bug was in the rulebook.

So eleven honest machines saw forged coins, agreed they were real, and signed.

Fifteen thousand machines would have signed too. More copies of the same mistake is agreement, not verification.

You might object: doesn't Bitcoin work the same way? Thousands of computers, mostly running the same software?

Mostly, yes. And Bitcoin has had rulebook bugs — one in 2010 briefly conjured 184 billion coins.

The difference is who checks, and for how long.

A forged Liquid coin had to fool eleven machines, once, in private.

A forged bitcoin has to fool every exchange, merchant and wallet it is ever spent to, in public, forever. The 2010 forgery survived a few hours.

And Bitcoin's rulebook has had a trillion-dollar prize sitting on it for sixteen years. Every year it survives is evidence the cheap bugs are gone.

Liquid's rulebook met its first $320 million test this week. It failed.

The bug is patched. The committee isn't — and can't be. It's how Liquid works.

Multi-media snippets

Matthew Crowder Alleges Blockstream Running Cloud Mining Ponzi Scheme

Bitcoin University

Liquid Network Security Incident: 4,000 Bitcoin Withdrawn

Bitcoin University

Matthew Crowder Speculates Liquid Hack May Be Inside Job

Bitcoin University

White hat hackers steal 4,000 Bitcoin ($320 million) from Liquid Network

Digital Asset News
17 sources