The address that drained Blockstream’s Liquid federation wallet on Sunday has broadcast a transaction that returns most of the bitcoin, after a negotiation carried out entirely inside Bitcoin transactions.
Blockstream has not made any public statement since Liquid’s first update on Sunday evening. Every message it sent to the attacker was placed in an OP_RETURN field and signed with PGP.
3,400 BTC sent back, 598.49955894 BTC returned to the originating address
The transaction sends 3,400 BTC, worth about $268 million based on the figures in the report, to the federation address. It also sends 598.49955894 BTC, about $47.2 million, back to the address that took the funds. That amount equals 15% of the 3,998.50 BTC withdrawn.
The transaction carries a fee of 1,768 satoshis, with a rate of 0.77 satoshis per virtual byte. All 16 inputs are marked for replace-by-fee, which means it can still be replaced by a different transaction while unconfirmed. As of 15:50 UTC on Monday, it had not yet confirmed.
Negotiation happened through OP_RETURN messages
Blockstream opened the channel at 19:31 UTC on Sunday with 1,000 satoshis and the message: “Please contact security@blockstream.com.”
It then sent two encrypted messages early Monday, at 01:33 and 01:49 UTC. The second was labeled as Electrum BIE1 ECIES encrypted to the key behind the attacker’s address.
At 02:20 UTC, the attacker replied in the clear, spending its full balance to itself and writing: “sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok.”
Blockstream answered at 03:30 UTC with a PGP-signed “Yes, thank you.” Then at 11:46 UTC it sent another signed message: “Bridge nodes are patched, safe to return the funds.” The 3,400 BTC transaction came after that.
Nothing either side published on-chain sets out an agreed figure for what the attacker would keep, and neither side described the retained amount as a bounty. Two more encrypted messages remain unconfirmed in the mempool.
SideSwap says the L-BTC came from an Elements software bug
SideSwap, the Liquid Federation member whose peg-out authorization key was used, published its explanation of the mechanism on Sunday at 21:19 UTC.
“Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service,” the company wrote. It said the service processed the request like any other order: the L-BTC was burned on Liquid with a valid peg-out authorization, and at 14:28 UTC the Liquid Federation paid 3,996 BTC to the customer’s Bitcoin address.
SideSwap said Blockstream later established that the L-BTC in that order “was created through a bug in the Elements software,” and that neither its key nor any of its systems had been compromised. “Our service had no way to tell those coins from any other L-BTC.”
An earlier transaction at 14:01 UTC sent 2.5 BTC to the same address before the order described by SideSwap. Together, the two peg-outs totaled 3,998.4975 BTC.
Wallet remains only slightly above outstanding L-BTC if the return confirms
The federation wallet currently holds 197.47 BTC confirmed. If the return transaction confirms, that balance would rise to 3,597.47 BTC.
Outstanding L-BTC stands at 197.30 BTC according to the explorer’s peg accounting, made up of 18,356.93 BTC in peg-ins, 18,149.60 BTC in peg-outs, and 10.03 BTC burned.
Bridge nodes are still disabled on Liquid’s account, so new transactions are not reaching the network. Liquid has not posted since Sunday. The latest entry on the Liquid blog is a technical explainer from July. Neither Blockstream’s account nor the account of chief executive Adam Back has mentioned the incident, and both last posted on Sept. 4.
Bitcoin traded at $78,855, down 0.90% over 24 hours, according to CoinGecko.
Attacker address turned into a public message board
The attacker’s address has become a public message board. Wallet developers have paid to advertise there. One message thanks a bitcoin-buying site, another promotes a memecoin, and several contain unverified accusations naming Blockstream staff and Bitcoin developers.
None of those messages is signed, and any address can write to another.
Blockstream’s messages stand out because they are PGP-signed. That is what allows the attacker to verify who is on the other side, and it is the only communication channel either party has used.

