The self-described whitehats who pegged 3,996 BTC out of the Liquid Network on Sunday 6 September returned 3,400 of them on Monday afternoon, kept 598.5, and on Wednesday morning turned the on-chain conversation with Blockstream into an ultimatum. In a transaction confirmed at 11:45:49 UTC on 9 September in block 966,199, sent from the address that holds the remaining coins, they wrote: “You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess.” The message, which Bitcoin.com News reported at 14:20 UTC on Wednesday and which the desk read directly from the transaction at 06:11 UTC on Thursday, opens by accusing Blockstream of having “allocated only $1.5M (maybe even 0) to secure $5B assets,” calls that “a flagrant neglect of security and a sign of complete mismanagement,” describes the company as “delusional, greedy, and arrogant to this very day,” and closes: “Anyway we are going to publish the privatekey to decrypt our conversations afterwards.” The dollar figures in it are the senders’ claims; the desk has found no Blockstream statement of its security budget and does not repeat the numbers as fact.

The arithmetic behind the two percentages is the whitehats’ own, and it checks. The 598.49955894 BTC they kept is 14.98% of the 3,996 BTC that left the federation; that is the “15% loss.” Ten percent of 3,996 is 399.6 BTC, which at Tuesday’s Bitstamp close of $78,281.65 is $31.3 million; the coins they are holding are worth $46.9 million at the same price, and the 3,400 they returned $266.2 million. So the proposal, read plainly, is that Blockstream pay roughly 400 coins’ worth from its own money, presumably to get roughly 600 back — the message does not actually say so — with the alternative that the sidechain’s token holders absorb the difference. This is the fifth calendar day of an incident that the desk covered on Monday morning, when the coins had not yet moved and the exchange between the parties was still polite.

Monday, hour by hour: a signed “safe to return,” a return of 3,400.00000000, and a frown

Everything since our last report is on the Bitcoin blockchain, and the desk pulled the full transaction list of the whitehat address, bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, at 06:11 UTC on Thursday: 287 transactions touch it, of which thirteen were sent from it, and only those thirteen — plus four sent by the Blockstream address bc1qn8mg… — are the conversation. All times are UTC. At 11:46:42 on Monday 7 September, in block 965,922, the Blockstream address sent a PGP-signed message reading “Bridge nodes are patched, safe to return the funds.” The desk fetched blockstream.com/pgp.txt again and verified the signature: it is good, made with the key whose fingerprint ends 6844 A2D6, at 09:04:57 UTC — two hours and forty-two minutes before the transaction carrying it confirmed. That is the fourth and, as of Thursday morning, the last message Blockstream has written to the chain.

At 12:43:33, block 965,930, the whitehats replied from the address holding the coins: “plz confirm again that we are sending the coins back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr” followed by “More details about the vuln fix:” and a PGP-encrypted block the desk cannot read. At 15:31:46, block 965,948, another encrypted block. And at 16:09:25, block 965,950, a fifteen-input transaction spent 3,998.49957662 BTC from the whitehat address into two outputs: 3,400.00000000 BTC to bc1qdlld6…, the peg address the whitehats had tagged with 1,000 satoshis in their first message on Sunday evening and named in text at 02:20 on Monday, and 598.49955894 BTC back to themselves. The miner fee was 1,768 satoshis. There was no OP_RETURN on that transaction and no confirmation from Blockstream preceding it in the chain; the “confirm again” request of 12:43 has no on-chain answer.

Then the tone changed. At 18:35:17, block 965,962, two transactions from the whitehat address carried two more encrypted blocks. At 21:03:23, block 965,973, a transaction from the same address carried an OP_RETURN of exactly two bytes, 0x3a 0x28 — a colon and an open parenthesis, the ASCII “:(”. Bitcoin Magazine, which reported the return on Monday, rendered it as a frowning-face emoji; the bytes are ASCII, and the desk prints them as sent. On Tuesday 8 September at 09:41:24, block 966,052, another encrypted block; at 14:25:31, block 966,087, an encrypted block and, in a separate transaction in the same block, the plain sentence “All messages will be in plaintext.” Twenty-one hours later came the demand. Between Monday 11:46 and Thursday 06:11 the Blockstream address wrote nothing.

Where the coins are, and where Liquid is

At 06:11 UTC on Thursday, the whitehat address held 598.50040069 BTC, the returned 598.5 plus the accumulated dust of strangers’ advertising transactions, and nothing from it was in the mempool. The peg address held 3,601.47203226 BTC across 589 transactions, up 3,404.00 from the 197.47 the desk recorded on Monday morning — the 3,400 return, the one-thousand-satoshi tags the whitehats attached to each of their messages, and a separate 4.0 BTC received at 08:13 UTC on Wednesday from three addresses that appear nowhere else in this sequence, whose sender the desk cannot identify. CertiK’s incident analysis of 7 September labels bc1qdlld6… as the “Liquid Federation Bitcoin peg wallet,” and Liquid’s own status report, as rendered by PANews on Wednesday, describes the reserve as having fallen “from approximately 4,205 to 197 BTC at one point,” a figure that matches the address to the coin; on Monday the desk declined to call the address federation-controlled without a Blockstream source, and it now has two.

The sidechain itself has not moved. Blockstream’s Liquid explorer returned block height 4,051,232 as its tip when the desk queried it at 06:17 UTC on Thursday, the same height NFTevening reported on Tuesday with a timestamp of 04:49 UTC on Monday 7 September. Liquid’s account on X posted a status report on Tuesday 8 September which, in PANews’s English rendering on Wednesday, says that “a vulnerability in the Elements software range proof verification cache was exploited,” that the attacker “minted approximately 4,000 LBTC without BTC reserve backing and exchanged them for BTC via SideSwap,” and that an emergency Elements v23.3.4 was coming. On Wednesday, per a second PANews rendering of a second Liquid post, the release was live, functionary nodes had “immediately begun upgrading,” and the restart would run in three phases: resume block production with the peg still suspended, replay verified transactions, and “resume Peg operations after the network state is fully restored and fund returns are confirmed.” The desk could not fetch the X posts themselves; the quotation marks are PANews’s wording. That last clause ties the peg’s reopening to the 598.5 BTC.

Samson Mow, whose post on X CoinDesk quoted at 04:41 UTC on Tuesday, said that “approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers,” that “the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart,” and that users should “not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted.” Cointelegraph, in a piece updated at 01:39 UTC Wednesday, wrote that “neither Blockstream nor Liquid publicly described the outstanding Bitcoin as a bounty or disclosed any repayment terms,” and quoted Ledger’s chief technology officer Charles Guillemet saying that if the outstanding coins were a negotiated reward, the arrangement looked “more like extortion than white-hat hacking.” The desk has found no Blockstream response, on-chain or off, to Wednesday’s demand, and no published reconciliation of L-BTC in circulation against bitcoin held.

What the bug was

CertiK’s analysis, published Monday, locates the flaw in Elements’ cache of already-verified range proofs — the cryptographic proofs that a confidential Liquid transaction’s amounts balance. “The issue stemmed from an ambiguous cache-key encoding in the rangeproof verification cache, allowing two different validation inputs to produce the same cached entry,” it writes; an earlier commit had tried to bind each cache entry to its full verification context but “fed the raw fields into one SHA-256 stream without encoding their lengths.” In plain terms, a node that had verified one proof could be made to believe it had verified a different one, and an attacker who arranged the collision could get 4,000 L-BTC credited without depositing bitcoin. Liquid’s Wednesday note, in PANews’s rendering, says v23.3.4 “strengthens the cache keys used for Range Proofs” and that the release was reviewed by outside teams it names as Bitcoin Red Team and Alpen Labs among others. As Monday’s guide set out, this is a consensus failure, not a custody failure: no key was stolen, and the federation’s signers paid out exactly what the sidechain’s broken accounting told them to.

The marker, graded early

On Monday the desk set T1: by 00:00 UTC on Monday 14 September 2026, at least 3,500 BTC has moved from bc1ql4mfu6… to bc1qdlld6… or another address Blockstream or Liquid publicly identifies as federation-controlled. The figure that has moved is 3,400.00000000, and it moved under ten hours after the marker was set. Unless a further 100 BTC leaves the whitehat address for the peg by Sunday midnight, T1 fails, and the desk will grade it a fail; the reasoning the marker gave for expecting more — that “most” in the whitehats’ message meant something close to all — was wrong by the width of the bounty they had decided on before Blockstream ever replied. What the marker got right is the destination, the mechanism and the speed: the coins went where the whitehats said, on-chain, within a day of the patch. Today’s companion guide, Field Guide #45, sets out how to read a demand like Wednesday’s, and the markers piece carries V1, the restart marker, which the three-phase plan has made harder to pass by 30 September, not easier.

Sources: mempool.space for the 9 September transaction and every other transaction, timestamp, block height, byte and balance in this article, pulled at 06:11 UTC on 10 September; blockstream.com/pgp.txt for the key against which the 7 September signature was verified; blockstream.info/liquid for the sidechain tip at 06:17 UTC; Bitcoin.com News, 9 September, 14:20 UTC; CoinDesk, 8 September, 04:41 UTC, for the Mow quotations; Cointelegraph, updated 9 September 01:39 UTC, for the bounty and Guillemet passages; Bitcoin Magazine, 7 September; PANews and PANews, both 9 September, for the English renderings of the two Liquid statements; CertiK, 7 September; NFTevening, 9 September 04:53 UTC. Prices are Bitstamp’s BTC/USD daily close for 9 September. The desk holds no L-BTC.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset or exchange-traded fund, including MSTR, STRC, L-BTC or HYPE. Do your own research and consult a licensed financial advisor before making investment decisions.