Samson Mow, CEO of JAN3 and a former Blockstream executive, has called on the unidentified actors behind the Liquid Network exploit to return the remaining Bitcoin after they sent back most of the funds taken during the attack.
Mow has published on-chain timelines of the talks. As of September 9, he referred to the counterpart as “Hacker,” after earlier using “white-hat hackers.” On-chain plaintext from the actors on September 9 demanded that Blockstream “pay 10% using your own money as bug bounty” or “cause all your holders a 15% loss,” and criticized Liquid’s security spend; Blockstream has not publicly accepted that as an authorized bounty.
Mow’s comments followed a series of on-chain and encrypted communications between Blockstream and the group, which has described itself as a white-hat security team.
3,400 BTC Returned
The incident began on September 6, when about 3,998.5 BTC (widely rounded to roughly 4,000 BTC) was withdrawn from Liquid’s federation wallet, which held about 4,200 BTC. The withdrawal created a significant shortfall in the Bitcoin backing Liquid’s L-BTC token. The drain was reported at about $320 million at the time.
The actors later said they would return most of the Bitcoin after the underlying vulnerability was fixed. Blockstream subsequently confirmed through a PGP-signed message that the affected bridge nodes had been patched.
The group then returned 3,400 BTC to the Liquid Federation wallet, representing about 85% of the Bitcoin withdrawn. Around 598.5 BTC, worth approximately $47 million, remained in an address linked to the actors.
The returned Bitcoin was worth about $268 million at the time. CertiK said the retained BTC could potentially serve as a bounty, but there has been no public confirmation of a formal bounty agreement.
SideSwap also returned about 4 BTC in fees it had received from processing the transaction, bringing the federation wallet’s balance to about 3,601.42 BTC.
How the exploit worked
The incident was linked to a vulnerability in the open-source Elements software used by Liquid. The flaw allowed the creation of roughly 4,000 unbacked L-BTC, which were then moved through SideSwap’s peg-out service and converted into real Bitcoin.
Liquid and SideSwap said SideSwap’s peg-out authorization key was used but not compromised. Independent and official descriptions point to a range-proof cache-key issue, not stolen federation keys.
Liquid said the incident did not involve compromised private keys. Instead, the exploit occurred at the transaction-validation level. The attackers were able to use the resulting L-BTC to trigger a legitimate peg-out process and drain Bitcoin from the federation wallet.
The network subsequently disabled its bridge nodes and paused L-BTC deposits and withdrawals while the vulnerability was addressed. Liquid said other issued assets such as USDT and RWAs were unaffected. Elements v23.3.4 was later released to harden range-proof cache keys.
Dispute Over the Remaining Funds
The return of 3,400 BTC has not ended the dispute over the remaining funds.
Mow has argued, in substance, that issued assets on Liquid belong to issuers and holders rather than a single company, and that a bounty should not be sized off the network’s overall asset base. He also questioned the decision to publicly acknowledge taking the Bitcoin while asking for a reward.
The remaining Bitcoin has become the focus of discussions between Blockstream and the actors. Communications have taken place through Bitcoin transaction messages and PGP-encrypted exchanges rather than conventional public channels.
The actors’ claim that they are white-hat hackers also remains part of the dispute. While they have returned most of the Bitcoin after the vulnerability was patched, no publicly disclosed agreement has established that the remaining funds constitute an authorized bug bounty.
Network restoration still underway
Liquid has yet to fully resume normal operations. Blockstream and federation members are working on additional security measures, resolving network issues and preparing for a controlled restart.
Liquid’s September 9 update outlined a staged plan: resume block production with peg operations still suspended; replay verified-valid transactions; resume pegs only after network state is restored, including a return of funds.
Mow has said the restoration process could take several days as developers review the fixes and work toward restoring full Bitcoin backing for L-BTC. Users have also been warned not to send Bitcoin to Liquid peg-in addresses until the network officially restarts. Official channels have also warned of phishing and fake “claim funds” sites.
For now, the focus remains on recovering the outstanding Bitcoin, completing the security fixes, and restoring Liquid’s operations without exposing the network to another exploit.
Also Read: Coinbase CEO Calls $400,000 Bitcoin Price by 2030 Reasonable
