CryptoJob Blog
  • Home
  • About
Sign in Subscribe
Web3 Careers

Blockstream Negotiated With Its Own Hackers Over Signed Bitcoin Transactions. Inside the 24 Hours.

No key was stolen, the network paused within hours, and 3,400 bitcoin came back at 16:09 UTC the next day. What the federation model got right, what it got wrong, and what Bitcoin sidechain jobs look like at the institutions that just found out.

Dan Kessler

20 Sep 2026 — 7 min read
Blockstream CEO Adam Back speaking on stage in front of a Bitcoin logo, hero for Bitcoin sidechain jobs guide on the Liquid hack
The custody model held. The software didn't.

TLDR

4,000 bitcoin left the Liquid federation wallet on a Sunday. No key was stolen.

Blockstream reached the hackers by signing a Bitcoin transaction. 3,400 came back by Monday.

The custody model held and the software didn't, and that's the job now.

At 16:09 UTC on Monday, September 7, a transaction landed in a Liquid Federation address carrying 3,400 bitcoin. Bitcoin's public record shows it. At the price that day, roughly $78,000, the coins were worth about $265 million, and they were 85% of what had left the same federation's wallet the previous afternoon. About 598.5 bitcoin, roughly $47 million, did not come with them. Nobody at Blockstream has said whether that was the price of getting the rest back.

The day before, at some point on Sunday, September 6, roughly 4,000 of the 4,200 bitcoin held in the Liquid federation wallet had been withdrawn in a single peg-out, about $320 million at the time and roughly 95% of the sidechain's reserves. Blockstream's notice called the actors "purported white-hat hackers." It said the peg-out authorization key belonging to SideSwap, which released the funds, "was not compromised, nor were any others." It said the team was "working on contacting them on-chain with a signed message." And it said, with a plainness that reads differently after the fact, "Liquid wallets will be impacted, and we're sorry for any inconvenience."

That's the whole arc: a withdrawal that shouldn't have been possible, a negotiation conducted in the only channel both sides could trust, and a return that was almost complete. The Bitcoin sidechain jobs behind each of those three things are what this story is about, and anyone weighing them can browse web3 jobs once they've seen how the model held.

CryptoJob: get hired in crypto. Fast, free, one profile. Start for free.

1. The withdrawal that shouldn't have been possible

Liquid is a federated Bitcoin sidechain. Real bitcoin sits in a wallet controlled by a group of known institutions, the federation, and the sidechain issues L-BTC against it, one for one. Peg in, and your bitcoin is locked and L-BTC minted. Peg out, and L-BTC is destroyed and bitcoin released. The design trades some of Bitcoin's trust-minimization for speed, confidentiality and faster settlement, and for years it avoided the bridge disasters that hit Ethereum-adjacent projects through the early 2020s.

What happened on September 6 was not a stolen key. TRM's account is the cleanest: a bug in the sidechain's validation software let the attackers forge the asset itself. Elements, the open-source code that powers Liquid, accepted L-BTC as valid that had no bitcoin behind it, and that L-BTC went through a legitimate peg-out via SideSwap and came out the other side as real bitcoin. Halborn adds the detail that makes it a story about process: the vulnerability had been identified and patched in the Elements codebase, publicly, before every node was running the fix.

Blockstream disabled the affected nodes and halted block production until the patch was applied across the network. Exchanges paused L-BTC deposits and withdrawals. And then the only move left was to talk.

2. How a negotiation works when there's no phone number

You can't email an address. What Blockstream could do, and said it was doing, was send a Bitcoin transaction to the attackers' address with a signed message attached, proving it came from the federation. The attackers could reply the same way. Watcher.Guru reported on September 7 that the hacker was communicating with network maintainers through on-chain Bitcoin transactions and intended to return the bitcoin after the vulnerability was fixed.

That sequence, patch first and return second, is the negotiation. The attackers' leverage was the bitcoin. Blockstream's leverage was that a paused network with a patched bug is worth nothing to hold hostage, and that a return would let the "white hat" description stand. Both sides moved within 24 hours. The 3,400 bitcoin arrived at 16:09 UTC the next day.

The 598.5 bitcoin that didn't arrive is where the story stays open. The Hacker News notes that neither Blockstream nor Liquid has said publicly whether that bitcoin is part of an agreement. TRM continues to track it and calls the white-hat claim unverified. It's either a bounty or it's the loot, and the federation isn't saying which.

Timeline of the Liquid Network hack and the 24-hour on-chain negotiation, for Bitcoin sidechain jobs
About 24 hours from drain to return. Five points from the incident, and the fifth one, 598.5 BTC with its status unstated, is where the story stays open.

3. How it works inside

The federation is the institution here, and it's worth understanding as an employer. Liquid's functionaries are a set of known, vetted companies, exchanges, custodians and infrastructure firms, that each run the software holding a share of the multi-party wallet. Blockstream builds the technology and coordinates; the members operate. When Blockstream "disabled the affected nodes," that meant reaching those members and getting them to act.

So the Bitcoin sidechain jobs in this story sit in three places. At Blockstream: the engineers who maintain Elements, wrote the fix, coordinated the rollout and drafted the signed message. At the federation members: the operations and security people who run functionary nodes, who had to confirm their version and hold their peg-out capacity while the patch propagated. And at the exchanges that list L-BTC, which paused deposits within hours and now have to decide when to resume.

The infrastructure guide covers node operations at the level of validators and DevOps; a functionary is that role with a share of $320 million behind it. The Bitcoin jobs guide covers the Bitcoin-native companies, and Liquid's members are drawn from that world. Bands there run $150K to $250K for the engineering side, per the protocol engineer guide.

4. What people who work there say

Nobody inside the federation has spoken on the record about the weekend, and I'd rather say that than pretend. What exists is Blockstream's own language, which is unusually direct for an incident notice, and two outside readings that frame the stakes.

Diagram of the three employers in the Liquid federation model and what each did during the hack
One sidechain, three payrolls. Blockstream maintains the code, the federation members run the nodes and hold the keys, the exchanges decide when L-BTC trades again.
"Liquid wallets will be impacted, and we're sorry for any inconvenience." Liquid Network, September 6 post on X, as reported by PYMNTS

The peg-out authorization key "was not compromised, nor were any others." Blockstream incident notice, as reported by The Hacker News

Read those two together and you have the federation's position: the custody model held and the software didn't, and we'll say so plainly. That's a more honest posture than most incident notices manage.

The Bitcoin Manual, writing while the funds were still out, put the structural worry in one line: after the exploit, the reserve backing all circulating L-BTC "dropped from over 4,200 BTC to roughly 197 BTC," which it called "the peg being, for all practical purposes, unbacked." That was true for about 24 hours. TRM's reading after the return is that the reserve sits at roughly 86% of L-BTC outstanding, which is not a full reserve and not a collapse either.

5. What it's like to work at a federation member now

The model's pitch was that a small set of vetted institutions co-signing a wallet is safer than an anonymous bridge. On September 6 that pitch was half right. Nobody's key was stolen; the multi-party custody worked exactly as designed. What failed was the validation layer every member trusted, and no amount of vetting the members would have caught a bug in the software they all ran.

For someone considering a functionary or federation role, that's the job description now. The custody part is solved and boring, which is what you want. The software-trust part is the open question, and the people hired next will be the ones who can answer it: staged rollouts, independent validation of the peg invariant, and a monitor that notices when 95% of a reserve moves.

Binance, Coinbase, Kraken and 17 more are hiring today on CryptoJob

The verdict

The federation passed the test it was designed for: nobody's key was compromised, the network was paused within hours, and 85% of the bitcoin came back inside a day through a channel both sides could verify. It failed the test it wasn't designed for, which is that a single validation bug let anyone forge the asset the whole model exists to protect. Bitcoin sidechain jobs are a good career for someone who wants to solve the second problem at institutions that just learned they have it; they're the wrong career for someone who wants the custody model to have been enough. Either way, browse web3 jobs and see which federation members and exchanges are staffing security this month.

CryptoJob: one profile, one click, every crypto role. Unlimited applications, zero cost.

FAQ

Who runs the Liquid federation?

A set of known institutions, exchanges, custodians and infrastructure firms, each operating a functionary node that holds a share of the multi-party wallet backing L-BTC. Blockstream develops the Elements software and coordinates the network.

Was Bitcoin itself hacked?

No. Bitcoin's main chain and protocol were unaffected. The flaw was in Elements, the sidechain software, and the coins that moved were real bitcoin leaving a sidechain reserve wallet.

Is the $47 million a bounty?

Nobody has said. Neither Blockstream nor Liquid has stated publicly whether the 598.5 bitcoin that was not returned is part of an agreement, and TRM continues to track it.

Related guides

  • Bitcoin Jobs in 2026: Lightning, Mining and the Companies Hiring
  • Blockchain Infrastructure Jobs: Nodes, Validators and DevOps
  • How to Get a Job at a Crypto Exchange

Read more

Halted stock terminal beside a live bonding curve, hero for launchpad developer jobs guide

Pump.fun Now Prices Memecoins in Tokenized Nvidia. Here's What Breaks.

Pump.fun opened 93 new quote assets on Wednesday and its fee docs don't cover any of them. Here's the engineering problem that creates, the incidents that already happened at this exact step, and the launchpad developer jobs it opens.

By Tiago Sousa 22 Sep 2026
Stacked tax statements and forms with a pen on a desk

Paid in Crypto? How Your Taxes Actually Work in 2026

Crypto pay is taxed twice in most countries, once as income and once at sale. The 2026 rules explained without the jargon.

By Karin Holm 22 Sep 2026
Thick printed bill with one page flagged, hero for crypto regulatory affairs jobs guide

The CLARITY Act Just Invented a Job. Someone Has to Register Your Protocol With the CFTC.

The 630-page revised CLARITY Act says any trading protocol a person or group can "control or materially alter" has to register with the CFTC. That's a job nobody has held. Bex Adeyemi on the four profiles that will get it, the six-second screen, and what to do this week.

By Bex Adeyemi 22 Sep 2026
Empty government building corridor with one door ajar, hero for crypto policy jobs guide

Stand With Crypto Contacted Congress 50,000 Times in August. Someone Organized That.

The industry's side of the CLARITY fight looked organized because it was. Bex Adeyemi on the four employers behind it, the four profiles they hire, why crypto-natives lose to Hill staffers, and the one afternoon that fixes that.

By Bex Adeyemi 21 Sep 2026
CryptoJob Blog
  • Sign up
Powered by Ghost

CryptoJob Blog

Thoughts, stories and ideas.