Liquid, as a Bitcoin sidechain launched by Blockstream, was originally positioned as a "secure channel" to accelerate transactions and asset issuance, but has recently been drawn into a tug-of-war involving approximately 4,000 BTC. According to sources, as of September 7, 2026, a self-proclaimed white hat hacker exploited a vulnerability in the Liquid network and successfully extracted about 4,000 Bitcoins from the sidechain system. The hacker emphasized in public information that these funds were merely "held in custody" and would be returned after the vulnerability was confirmed and fixed. Unlike traditional security incidents, which are communicated discreetly through email or private messages, both parties chose to move negotiations onto the Bitcoin main chain, using the OP_RETURN field in transactions to write text messages and engage in public deliberations over the conditions for return, progress of the fix, and security verification. Blockstream subsequently stated through public channels that the relevant vulnerability had been fixed and demanded the self-proclaimed white hat to return approximately 4,000 BTC. However, the hacker insisted that the return was contingent on "when it can be considered truly fixed." This standoff conducted on-chain exposed Liquid's technical risks, the boundaries of the project's responsibilities, and users' trust in the custody security of the sidechain, all centered around an unresolved incident.
4,000 BTC lost, Liquid locked down by white hat
What is truly disheartening about the incident is not just the technical details, but the weight of that string of numbers—according to public information and on-chain records, the hacker extracted approximately 4,000 BTC from the sidechain system during an exploit of a vulnerability in the Liquid network. Liquid, as a Bitcoin sidechain launched by Blockstream, was meant to accelerate mainnet transactions and asset issuance, yet at this moment it has turned into a channel through which significant assets have been "moved away." Although public materials have not disclosed the specific type of vulnerability or attack method, the scale alone marks this not as an ordinary test or operational error, but as a systemic shock capable of shaking participants' security expectations.
Even more dramatic, the attacker, who controlled approximately 4,000 BTC, repeatedly emphasized on-chain and through public channels that he was a "white hat" and that the funds were only temporarily held. He stated that the return would occur only after the Liquid vulnerability was fixed and all relevant nodes completed their patch upgrades. The problem is, when such a large volume of BTC is concentrated in the hands of a single actor for an extended period, Liquid users are compelled to trust an unverified personal promise, while the Bitcoin ecosystem must confront the psychological pressure of whether "sidechain custody can be abused." Even if the hacker continues to stress that he has no malicious intent, this asymmetric control itself has created a breach of trust between Liquid and the broader Bitcoin community.
On-chain negotiations: OP_RETURN as a public dialogue platform
In this tug-of-war surrounding approximately 4,000 BTC, Blockstream and the self-proclaimed white hat hacker did not choose encrypted emails or private channels, but instead moved the negotiations directly onto the Bitcoin main chain. Both parties published their positions and conditions by writing text in the OP_RETURN field within transactions: the hacker initially expressed a willingness to return "most" of the BTC, but then tightened the conditions in subsequent messages, stating that the Liquid vulnerability must first be fixed and all nodes upgraded before discussing return details; Blockstream responded in the same manner, emphasizing that the vulnerability had been fixed, detailing the technical progress, and publicly demanding the return of approximately 4,000 BTC. Each message is permanently recorded on the blockchain, allowing anyone to trace the rhythm and attitude of this negotiation through the sequence of transactions.
This on-chain visible form of negotiation has at least alleviated previous trust fractures at the information level: how conditions change and how the project responds are no longer just the parties' statements but a clear textual trail, allowing the community to discuss and exert pressure around the same set of public materials. However, its symbolic significance outweighs its actual binding force—OP_RETURN can only record "what was said," not automatically enforce "what will be done." As of September 7, 2026, public materials only describe the negotiation content and do not show any on-chain data indicating that the funds have actually been returned. This means the community is witnessing a transparent dialogue process, rather than a verifiable result of asset restitution. This transparent yet execution-lacking on-chain negotiation model itself is a complex sample left to the industry by this security incident.
Repair statements and trust games: who determines safety?
After the public negotiations reached a stalemate, Blockstream chose to first present its conclusion: the relevant vulnerabilities in the Liquid network "have been fixed," emphasizing through public channels that this is a key node in advancing incident resolution. Subsequently, they demanded that the self-proclaimed white hat hacker return approximately 4,000 BTC. For the project party, "vulnerability has been fixed" signifies a shift from technical emergency response back to asset remediation. The return of funds not only symbolizes risk convergence but is also a necessary step to prove to the outside world that the sidechain can still be trusted to operate.
However, the white hat's view of security is evidently more conservative. In previous on-chain and public communications, he repeatedly emphasized that funds would only be returned after the vulnerabilities were fixed and all nodes completed their patch upgrades. This insistence shifted the standard of security verification from "the code has been patched" to "the entire network environment no longer has similar attack surfaces." The issue is that existing materials have not presented Blockstream with a clear confirmation of "all nodes have been upgraded," nor is there new on-chain data indicating that the funds have indeed been returned. This has left both parties in an invisible tug-of-war regarding when they could declare that "the safety status has been restored." In the absence of a unified authoritative judgment and with no automatically enforceable on-chain terms, whether the project party and the white hat can eventually reach a consensus on the standard of "repair completion" becomes one of the most tension-filled and testing variables for the industry's trust mechanism in this incident.
Questions about Liquid sidechain security and concerns in the Bitcoin ecosystem
Liquid's positioning within the Bitcoin ecosystem was originally to represent "enhanced performance and flexibility outside the main chain": developed by Blockstream, it serves as a sidechain to accelerate Bitcoin transactions and asset issuance, regarded as a technical path to expand functionality without altering the main chain consensus. However, the incident involving approximately 4,000 BTC controlled by the white hat has forced the original design intention of "custody of Bitcoin on the sidechain" to undergo a reality pressure test—when funds are concentrated in the hands of a single party, and the return rhythm is tied to the vulnerability repair standards, whether the sidechain solution can still be seen as an extension of the main chain's security narrative rather than a weakening of it becomes a pointed question facing all participants.
According to AiCoin data, the project party and white hat chose to negotiate publicly on the main chain through the OP_RETURN field in Bitcoin transactions. This has left a clear trail of disputes on the Bitcoin main chain for a risk that was originally confined within Liquid, amplifying the community's intuitive sense of the tension between "the main chain's conservative security" and "the sidechain's exposure to new risks." On the main chain side, the security narrative remains a well-tested consensus rule and a protocol with minimal changes; on the sidechain side, while pursuing speed and flexibility, it exposes weaknesses in audit, risk isolation, and custody trust. Because the Liquid incident concentrates this set of contradictions on the retention of 4,000 BTC, it is viewed as a typical case in the Bitcoin ecosystem regarding sidechain security, auditing, and risk isolation, forcing more to acknowledge that expanding Bitcoin's capacity under the premise of "not altering the main chain" does not automatically mean that systemic security issues have been resolved.
White hat return and the reconstruction of trust in Liquid still await observation
At this current stage, the negotiation over the Liquid incident has narrowed from "whether there is a vulnerability" to two core focal points: how to return approximately 4,000 BTC, and who determines that "the vulnerability has been fixed and the system is safe." The hacker, claiming to be a white hat, has explicitly tied the return of funds to the conditions of vulnerability repair and all nodes completing their patch upgrades, while Blockstream has emphasized in public statements that relevant vulnerabilities in Liquid have been fixed and demanded the return of all BTC. The problem is that both sides do not agree on the criteria for "repair completion" and "safety availability." As of September 7, 2026, public materials only show that the project party has made a return request, yet there is no on-chain or official information confirming whether these BTC have returned to project or user-controlled addresses. The final disposition of the funds remains uncertain. Meanwhile, both parties continue to issue text messages via the OP_RETURN field in Bitcoin transactions, partly exposing this negotiation to on-chain visibility and allowing external observers to track the direction of subsequent messages. The incident has prompted discussions in the community about "how to establish rewards for white hats, how to disclose vulnerabilities, and how to cooperate with security researchers," but for Liquid and its parent company Blockstream, merely relying on technical repairs is far from sufficient to balance the custodial and reputation pressures brought about by this turmoil. Whether clear return records appear in subsequent on-chain information, whether the project establishes a transparent security disclosure mechanism, and whether the white hat cooperation rules can be clearly incorporated into a system will collectively determine whether this crisis can truly transform into a turning point for sidechain security governance.
Join our community, let’s discuss and grow stronger together!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

