Attackers stole nearly all of Liquid Network's Bitcoin reserve this week, then gave most of it back.
Attackers minted roughly 4,000 L-BTC, the token used on Blockstream's Liquid sidechain, without depositing the real Bitcoin required to back it. They ran the fake tokens through SideSwap, a legitimate conversion service that a bug couldn't distinguish from real L-BTC, tricking the Liquid Federation into releasing 3,998 actual BTC (worth about $313 million) to the attackers' wallets. Liquid halted new transactions immediately while Blockstream scrambled to patch the affected bridge nodes. The attackers then messaged operators on-chain, promising to return the funds once every node was patched, and after Blockstream confirmed the fix, they sent back 3,400 BTC, leaving roughly 598 BTC (about $47 million) still outstanding.
The instructive part isn't the hack itself, it's the negotiation. Ransomware crews demand payment to stay quiet; these attackers demanded a patch before they'd give the money back, functioning less like thieves and more like an unlicensed, extremely blunt bug-bounty program. It's also a reminder that sidechains and bridges, the plumbing that lets Bitcoin move fast between systems, remain a persistent weak point in crypto security, the same category of flaw behind years of bridge exploits elsewhere in the industry.
Whether the outstanding 598 BTC ever comes back is now a matter of the hackers' goodwill, not code, which is exactly the kind of security model nobody should be relying on.