A bug fix on the Bitcoin sidechain appears tied to the recovery of most of the funds taken in a bridge exploit.
Attackers who exploited a bridge vulnerability on the Liquid Network are reportedly sending back most of the Bitcoin they took. U.Today reported that hackers plan to return the bulk of roughly 4,000 BTC stolen in the incident. Crypto.news separately reported that 3,400 BTC has already been recovered following a fix to the bug that enabled the breach.
The two figures do not match exactly, and the reporting leaves open exactly how much has been returned versus how much remains outstanding. Some accounts describe an ongoing return of "most" of the funds, suggesting the process may still be underway rather than complete.
Liquid Network operates as a Bitcoin sidechain designed to enable faster settlement and confidential transactions for exchanges and institutional users. Bridges connecting sidechains to the main Bitcoin blockchain have repeatedly proven to be weak points across the industry. They require complex code to lock and unlock assets across two separate systems, and that complexity has historically created opportunities for exploitation.
The apparent return of stolen funds, rather than their permanent loss, fits a pattern seen in several past bridge incidents. Attackers sometimes return assets after facing scrutiny, technical tracing efforts, or the practical difficulty of laundering large sums of Bitcoin without detection. In other cases, white-hat arrangements or negotiated bounties have led to partial or full restitution.
Details on the identity of the attackers, the precise mechanism of the bridge bug, and the timeline of the fix have not been fully disclosed in available reporting. It also remains unclear whether any bounty or amnesty arrangement was offered to encourage the return of funds, a common feature of past bridge hack resolutions.
The incident nonetheless underscores a persistent risk within Bitcoin's broader ecosystem of sidechains and layer-two systems. As custody and market structure around Bitcoin-adjacent infrastructure grow more complex, bridge security remains a recurring point of failure. Users and institutions relying on such systems face ongoing exposure until stronger technical safeguards become standard across the sector.
A large-scale return of stolen Bitcoin, if confirmed at the scale described, would limit the lasting financial damage from the exploit. It could also ease concerns among users and partners of the Liquid Network about permanent loss of funds. Even so, the episode is likely to renew scrutiny of bridge security across Bitcoin sidechains and layer-two networks more broadly.
Exchanges and custodians that rely on similar bridging technology may face pressure to review their own risk exposure. Market participants often treat such incidents as a signal to reassess counterparty and infrastructure risk before committing further capital to affected platforms.
As recovery efforts continue, the exact scale of returned funds and the full circumstances of the exploit remain to be confirmed through further reporting.
A bridge exploit reportedly allowed attackers to take roughly 4,000 BTC from the Bitcoin sidechain, according to available reporting.
Reports differ slightly. One source cited a recovery of 3,400 BTC after a bug fix, while another described hackers returning most of the roughly 4,000 BTC taken.
The incident is linked to a bug in the network's bridge system, which was reportedly fixed as part of the recovery process, though full technical details have not been disclosed.
Available reporting does not confirm whether the full amount will be recovered, only that a significant portion has been or is being returned.
Malone Lam Case: Sources Clash on Jurisdiction
September 7, 2026
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect