Blockstream Negotiated With Its Own Hackers Over Signed Bitcoin Transactions. Inside the 24 Hours.
No key was stolen, the network paused within hours, and 3,400 bitcoin came back at 16:09 UTC the next day. What the federation model got right, what it got wrong, and what Bitcoin sidechain jobs look like at the institutions that just found out.
TLDR
4,000 bitcoin left the Liquid federation wallet on a Sunday. No key was stolen.
Blockstream reached the hackers by signing a Bitcoin transaction. 3,400 came back by Monday.
The custody model held and the software didn't, and that's the job now.
At 16:09 UTC on Monday, September 7, a transaction landed in a Liquid Federation address carrying 3,400 bitcoin. Bitcoin's public record shows it. At the price that day, roughly $78,000, the coins were worth about $265 million, and they were 85% of what had left the same federation's wallet the previous afternoon. About 598.5 bitcoin, roughly $47 million, did not come with them. Nobody at Blockstream has said whether that was the price of getting the rest back.
The day before, at some point on Sunday, September 6, roughly 4,000 of the 4,200 bitcoin held in the Liquid federation wallet had been withdrawn in a single peg-out, about $320 million at the time and roughly 95% of the sidechain's reserves. Blockstream's notice called the actors "purported white-hat hackers." It said the peg-out authorization key belonging to SideSwap, which released the funds, "was not compromised, nor were any others." It said the team was "working on contacting them on-chain with a signed message." And it said, with a plainness that reads differently after the fact, "Liquid wallets will be impacted, and we're sorry for any inconvenience."
That's the whole arc: a withdrawal that shouldn't have been possible, a negotiation conducted in the only channel both sides could trust, and a return that was almost complete. The Bitcoin sidechain jobs behind each of those three things are what this story is about, and anyone weighing them can browse web3 jobs once they've seen how the model held.

1. The withdrawal that shouldn't have been possible
Liquid is a federated Bitcoin sidechain. Real bitcoin sits in a wallet controlled by a group of known institutions, the federation, and the sidechain issues L-BTC against it, one for one. Peg in, and your bitcoin is locked and L-BTC minted. Peg out, and L-BTC is destroyed and bitcoin released. The design trades some of Bitcoin's trust-minimization for speed, confidentiality and faster settlement, and for years it avoided the bridge disasters that hit Ethereum-adjacent projects through the early 2020s.
What happened on September 6 was not a stolen key. TRM's account is the cleanest: a bug in the sidechain's validation software let the attackers forge the asset itself. Elements, the open-source code that powers Liquid, accepted L-BTC as valid that had no bitcoin behind it, and that L-BTC went through a legitimate peg-out via SideSwap and came out the other side as real bitcoin. Halborn adds the detail that makes it a story about process: the vulnerability had been identified and patched in the Elements codebase, publicly, before every node was running the fix.
Blockstream disabled the affected nodes and halted block production until the patch was applied across the network. Exchanges paused L-BTC deposits and withdrawals. And then the only move left was to talk.
2. How a negotiation works when there's no phone number
You can't email an address. What Blockstream could do, and said it was doing, was send a Bitcoin transaction to the attackers' address with a signed message attached, proving it came from the federation. The attackers could reply the same way. Watcher.Guru reported on September 7 that the hacker was communicating with network maintainers through on-chain Bitcoin transactions and intended to return the bitcoin after the vulnerability was fixed.
That sequence, patch first and return second, is the negotiation. The attackers' leverage was the bitcoin. Blockstream's leverage was that a paused network with a patched bug is worth nothing to hold hostage, and that a return would let the "white hat" description stand. Both sides moved within 24 hours. The 3,400 bitcoin arrived at 16:09 UTC the next day.
The 598.5 bitcoin that didn't arrive is where the story stays open. The Hacker News notes that neither Blockstream nor Liquid has said publicly whether that bitcoin is part of an agreement. TRM continues to track it and calls the white-hat claim unverified. It's either a bounty or it's the loot, and the federation isn't saying which.

3. How it works inside
The federation is the institution here, and it's worth understanding as an employer. Liquid's functionaries are a set of known, vetted companies, exchanges, custodians and infrastructure firms, that each run the software holding a share of the multi-party wallet. Blockstream builds the technology and coordinates; the members operate. When Blockstream "disabled the affected nodes," that meant reaching those members and getting them to act.
So the Bitcoin sidechain jobs in this story sit in three places. At Blockstream: the engineers who maintain Elements, wrote the fix, coordinated the rollout and drafted the signed message. At the federation members: the operations and security people who run functionary nodes, who had to confirm their version and hold their peg-out capacity while the patch propagated. And at the exchanges that list L-BTC, which paused deposits within hours and now have to decide when to resume.
The infrastructure guide covers node operations at the level of validators and DevOps; a functionary is that role with a share of $320 million behind it. The Bitcoin jobs guide covers the Bitcoin-native companies, and Liquid's members are drawn from that world. Bands there run $150K to $250K for the engineering side, per the protocol engineer guide.
4. What people who work there say
Nobody inside the federation has spoken on the record about the weekend, and I'd rather say that than pretend. What exists is Blockstream's own language, which is unusually direct for an incident notice, and two outside readings that frame the stakes.

"Liquid wallets will be impacted, and we're sorry for any inconvenience." Liquid Network, September 6 post on X, as reported by PYMNTS
The peg-out authorization key "was not compromised, nor were any others." Blockstream incident notice, as reported by The Hacker News
Read those two together and you have the federation's position: the custody model held and the software didn't, and we'll say so plainly. That's a more honest posture than most incident notices manage.
The Bitcoin Manual, writing while the funds were still out, put the structural worry in one line: after the exploit, the reserve backing all circulating L-BTC "dropped from over 4,200 BTC to roughly 197 BTC," which it called "the peg being, for all practical purposes, unbacked." That was true for about 24 hours. TRM's reading after the return is that the reserve sits at roughly 86% of L-BTC outstanding, which is not a full reserve and not a collapse either.
5. What it's like to work at a federation member now
The model's pitch was that a small set of vetted institutions co-signing a wallet is safer than an anonymous bridge. On September 6 that pitch was half right. Nobody's key was stolen; the multi-party custody worked exactly as designed. What failed was the validation layer every member trusted, and no amount of vetting the members would have caught a bug in the software they all ran.
For someone considering a functionary or federation role, that's the job description now. The custody part is solved and boring, which is what you want. The software-trust part is the open question, and the people hired next will be the ones who can answer it: staged rollouts, independent validation of the peg invariant, and a monitor that notices when 95% of a reserve moves.

The verdict
The federation passed the test it was designed for: nobody's key was compromised, the network was paused within hours, and 85% of the bitcoin came back inside a day through a channel both sides could verify. It failed the test it wasn't designed for, which is that a single validation bug let anyone forge the asset the whole model exists to protect. Bitcoin sidechain jobs are a good career for someone who wants to solve the second problem at institutions that just learned they have it; they're the wrong career for someone who wants the custody model to have been enough. Either way, browse web3 jobs and see which federation members and exchanges are staffing security this month.

FAQ
Who runs the Liquid federation?
A set of known institutions, exchanges, custodians and infrastructure firms, each operating a functionary node that holds a share of the multi-party wallet backing L-BTC. Blockstream develops the Elements software and coordinates the network.
Was Bitcoin itself hacked?
No. Bitcoin's main chain and protocol were unaffected. The flaw was in Elements, the sidechain software, and the coins that moved were real bitcoin leaving a sidechain reserve wallet.
Is the $47 million a bounty?
Nobody has said. Neither Blockstream nor Liquid has stated publicly whether the 598.5 bitcoin that was not returned is part of an agreement, and TRM continues to track it.