How the Liquid Network drain was negotiated in public — one OP_RETURN message at a time — and how anyone with a terminal could read it live.
Somewhere in Bitcoin's blockchain, confirmed forever between billions of dollars of transactions, there is now a sad face.
Two bytes. Hex 3a28. Decoded: :(
It was published on September 7, 2026, by whoever had just returned 3,400 BTC — roughly $268 million — to the Liquid Network's federation wallet, while keeping 598.5 BTC. It appears to be their closing statement in what may be the strangest negotiation in Bitcoin's history: not because of the amounts, but because of where it happened.
The entire conversation — first contact, identity proof, terms, objections, settlement — was written inside Bitcoin transactions. In public. Permanently. Readable by anyone on Earth with a terminal.
I read it live from mine. This is that story, with every message decoded — and every transaction ID included, so you can verify every word yourself.
What happened
On September 6, roughly 4,000 BTC (~$320M) left the federation wallet backing Blockstream's Liquid Network — a Bitcoin sidechain where users lock real BTC to receive faster, more private L-BTC. The wallet held about 4,200 BTC before the withdrawal. Afterwards: a little over 200. About 95% of the reserve, gone in one move.
No keys were stolen. No signer was phished. According to Liquid's statement, the withdrawal went through SideSwap's peg-out authorization path, and the authorization key itself was not compromised — the working theory points to a software vulnerability that let the attacker obtain L-BTC they shouldn't have had, then peg out to real BTC with signatures that were, technically, perfectly legitimate.
The protocol held. The periphery bled.
And then, minutes after the funds landed, the address holding them spoke.
The unlikely channel
Bitcoin transactions have a feature called OP_RETURN: an output type that carries a small payload of arbitrary data instead of spendable coins. It was standardized in Bitcoin Core v0.9.0, back in March 2014, precisely to give people a clean way to embed data on-chain. People have used it for timestamps, proofs, protocol messages — and occasionally, for messages meant for one specific reader, delivered in front of everyone.
An OP_RETURN message costs almost nothing, cannot be edited, cannot be deleted, and cannot be censored. Which makes it a surprisingly rational channel for negotiating the return of $320 million: no email to spoof, no DM to fake — and, combined with PGP signatures, cryptographic proof of who is speaking.
Everything below was decoded with btc-toolkit, an open-source Bitcoin CLI I maintain. Run the same commands; you'll read the same bytes.
The conversation, message by message
1. First contact — block 965,818
The address holding the drained coins moved them — all ~3,998.5 BTC, for a fee of 269 satoshis — in a transaction carrying a 37-byte note:
$ btc-toolkit opreturn c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
✓ Found 1 OP_RETURN output(s):
Output #0
├─ Size: 37 bytes
├─ Hex: 776520617265207768697465686174732e20636f6e74616374207573206f6e20…
└─ Message: we are whitehats. contact us on chain
Three hundred and twenty million dollars moved, with a note attached, for the price of a stick of gum.
2. Blockstream picks up the phone — block 965,822
A Blockstream-linked address answered in kind: 1,000 satoshis sent to the attacker, carrying a 39-byte reply.
$ btc-toolkit opreturn 91271efcbb5ab29abfc38ae635f0644e3ba042aad56f92d40136e1dde4742fe8
└─ Message: Please contact security@blockstream.com
3. Proof of identity — block 965,865
The conversation stayed on-chain. Blockstream escalated there too, with a 1,297-byte message that is a small masterpiece of operational security. It contains a payload encrypted to the key behind the attacker's own address (Electrum BIE1 ECIES — meaning only whoever controls that address can read it), plus a detached PGP signature, plus instructions for the whole world to verify it:
$ btc-toolkit opreturn bd81219691eb1e22475c5985d847fa888c38f1b6d2cb2b7193f54d0cfa72394c
└─ Message: Encrypted to the key behind bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte
(Electrum BIE1 ECIES): QklFMQLaSmCm5qeNvxcJnaVGKqIVzH5Y3oL2OrBYayfMegxjx…
Detached signature by security@blockstream.com.
Public key: https://blockstream.com/pgp.txt
Fingerprint: 1176 542D A98E 71E1 3372 2EF7 4AC8 CC88 6844 A2D6
Verify: gpg --import pgp.txt && gpg --verify msg.asc msg.b64
-----BEGIN PGP SIGNATURE-----
…
=HAck
-----END PGP SIGNATURE-----
Yes — the signature's armor checksum happens to read =HAck. Whether that's a one-in-millions coincidence of base64 or someone at Blockstream grinding signatures for style, the chain does not say.
4. The offer — block 965,869
The attacker replied by moving the entire ~3,998.5 BTC balance again — each of their negotiation messages rode a transaction moving the full amount — this time asking, in 95 bytes:
$ btc-toolkit opreturn 3a3eac4a26395b8c2563aaf1eb8b1b77798c81c7d6337f51321827a244a480aa
└─ Message: sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok
That destination is Liquid's federation peg address. "Most," it would turn out, was doing a lot of work in that sentence.
5. The condition — block 965,875
Then came the twist that gave the "whitehat" claim some weight. Before returning anything, the attacker demanded the fix — in a 1,512-byte message with the vulnerability details encrypted to Blockstream's public key:
$ btc-toolkit opreturn 83825b2135dd0abac12c9dfe17f29ab81b3427e1ae864947b0bebce5e47c3c4b
└─ Message: Please fix the bug first. The chain is under risk at latest commit
right now. Make sure every node is patched. Then we will transfer
the money back safely after confirming the fix. The detail is as
follows (encrypted using https://blockstream.com/pgp.txt).
-----BEGIN PGP MESSAGE-----
…
A thief doesn't usually audit your remediation. Blockstream's reply, in the same block — 897 bytes, PGP-signed, to say three words:
$ btc-toolkit opreturn 8a444eed65c4584f138e08ee138f61490ef73e84f71e14dac3ca66c230cf7e97
└─ Message: -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Yes, thank you.
-----BEGIN PGP SIGNATURE-----
…
The next morning, a further signed message confirmed the bridge nodes were patched and it was safe to return the funds.
6. Settlement — block 965,950
The return transaction confirmed on September 7: exactly 3,400.00000000 BTC back to the Liquid federation address, with 598.5 BTC — about 15%, ~$47M — staying behind. No message in the negotiation ever named that figure, or called it a bounty.
$ btc-toolkit tx a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d
Epilogue — block 965,973
Encrypted messages went back and forth. And then, from the purported whitehats, the final word — all two bytes of it:
$ btc-toolkit opreturn d7e8837c51cc625c2c6365d371d376b035209fa01434d4933971d6428d6d6d52
Output #0
├─ Size: 2 bytes
├─ Hex: 3a28
└─ Message: :(
Whatever was said in those encrypted notes about the size of that 15%, it did not end warmly. As of this writing, the sad face is the last public word — and at least one more encrypted, signed message sits unconfirmed in the mempool. The story may not be over.
Meanwhile, the peanut gallery
Here is the part no headline captured: because the negotiating table was public, the whole world pulled up a chair.
Walk the attacker's address history and, between the PGP ceremonies, you'll find dozens of strangers' notes: pleading letters ("if you truly are white hat and return this, you'll not have only saved my family that includes a few month old baby…"), haggling ("Gift 8.5 odd BTC. No more, no less."), career advice ("Grant me 10BTC and I'll name my first born…"), waves of memecoin spam shilling a "Whitehat" token, classic doubler scams, and conspiracy graffiti accusing named executives — permanently, and permanently unverified. The blockchain doesn't fact-check; it only timestamps.
A $320M negotiation, and the replies section came with it.
Read it yourself — in two minutes
You don't have to trust this article. That's the entire point of it.
pip install btc-toolkit
btc-toolkit opreturn c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
btc-toolkit is a zero-dependency Python CLI (standard library only — nothing in your install to poison, which matters in a year of supply-chain attacks). No Bitcoin Core required; it talks to the Mempool.space public API by default, and with --api-url it can point every query at your own node instead, so nobody sees what you verify. Seven commands, 110 tests, MIT licensed.
Every transaction ID above is real. Decode them all, walk the address, find messages I didn't quote. You'll be reading the primary source — not my retelling of it.
This didn't start yesterday
People have been leaving permanent messages on Bitcoin for over a decade. A famous 2023 transaction carries 34 bytes declaring "Craig Wright is a liar and a fraud." The learnmeabitcoin project embedded its name in a null-padded 75-byte note. (And no — Satoshi's "Chancellor on brink of second bailout for banks" is not an OP_RETURN: it lives in the coinbase scriptSig of the genesis block. Common misconception.)
What changed this week is the stakes. OP_RETURN went from graffiti wall to negotiating table — and the table was public the entire time.
The moral
Two things were true at once this week.
Bitcoin itself has never been hacked — the base layer processed every one of these transactions, the theft and the return alike, exactly as designed. And the ecosystem around Bitcoin had one of its worst weeks on record — because software at the periphery failed, as software does.
The bridge between those truths is verifiability. The reason the whole world could follow a $320M ransom negotiation in real time — check the signatures, count the coins, read the sad face — is that Bitcoin's ledger is public, and every claim about it can be checked by anyone, with modest tools, in seconds.
That's not a slogan. It's a process. It's the only reason you didn't have to take my word for a single sentence above.
Don't Trust. Verify.
btc-toolkit is open source (MIT): github.com/devdavidejesus/btc-toolkit · pip install btc-toolkit
Top comments (0)