Articles

Client Alert: $320 Million Crypto Heist—What It Means for Asset Recovery and Who Pays

Date: September 30, 2026

On September 6, 2026, an attacker took about $320 million in bitcoin from the Liquid Network, a system run by Blockstream that exchanges and trading firms use to move bitcoin between each other quickly. The attacker returned 85 percent after negotiating and kept about $47 million, calling it a reward for finding the “flaw.” Taking funds first and then negotiating to keep a share is becoming a common pattern in large crypto thefts, and businesses, investors and insurers should decide how they would respond before it happens to them.

 

What clients need to know

  • An attacker cannot award itself a reward. A legitimate "bug bounty" is an offer a company publishes in advance to people who report flaws. Without that offer, funds an attacker keeps remain recoverable through ordinary civil claims such as conversion and unjust enrichment.
  • Anonymous attackers can be sued. US and English courts have frozen stolen crypto held by unidentified defendants and allowed them to be served through the same digital wallet that holds the funds.
  • Stolen bitcoin can be frozen only when it reaches a regulated business. No one can freeze bitcoin on the network itself. Recovery depends on reaching the exchange or trading desk where the attacker tries to turn it into cash.
  • Paying or conceding anything to an attacker carries sanctions risk. If the attacker is a sanctioned person, OFAC can impose penalties even if the victim did not know but later learned of the hacker’s identity or ties to a sanctioned entity and did not disclose. The two largest crypto thefts of April 2026 were attributed to North Korean state hackers.
  • The attacker is not the only party at risk. Customers holding the affected assets may bring claims against the companies that ran the system and wrote its software.
  • Insurance coverage depends on how the loss is characterized. A policy covering “theft” may not cover “software failure” or “business interruption,” and notice deadlines can be short. Insurers and coverage counsel should assess exposure now.


What to do now

Companies that operate crypto platforms or networks:

  • Adopt an incident playbook that names who talks to an attacker, what may be offered and when to run sanctions checks and call law enforcement.
  • Keep emergency court papers ready, including a complaint against unknown defendants, a TRO application and a declaration from a tracing firm.
  • Publish reward terms in advance, with a cap. A published bug bounty makes any other retention clearly unauthorized. An industry standard, the SEAL Whitehat Safe Harbor, offers a template.
  • Control how security fixes are disclosed. Don't announce a fix until every operator has installed it and it has been checked for related flaws. In the Liquid incident, publishing one fix exposed a second flaw.
  • Agree in advance who covers a loss. Where several companies run a shared system, their agreements should say who bears a shortfall and in what order.


Exchanges, custodians and trading desks

  • Set a fast process for freezing orders and law enforcement requests about accounts linked to stolen funds. English courts have held that an exchange holding identifiable stolen crypto may owe duties to the victim.
  • Review your exposure to "wrapped" tokens—assets like L-BTC that represent bitcoin held elsewhere by a third party. If the backing is lost or frozen, so is the value. Consider what you tell customers about that risk.


Funds, family offices and other holders

  • List your holdings of wrapped tokens and the terms that apply if redemptions are suspended, as Liquid's have been.
  • Check insurance coverage for theft and software-failure losses, including notice deadlines.
  • If you hold affected assets, keep records now. Claims will turn on timing and documentation.


How counsel can help

Counsel adds the most value before an incident and in the first 72 hours after one.
  • Readiness: reward terms, disclosure procedures and loss-sharing provisions in operating agreements.
  • Rapid response: working with blockchain tracing firms, seeking emergency freezing orders in US courts against unknown defendants and coordinating with counsel abroad.
  • Negotiating with attackers: structuring any return so that claims to the rest are preserved, with sanctions checks and a law enforcement strategy.
  • Recovery and disputes: pursuing claims against attackers and intermediaries, and defending claims by customers and business partners. For substantial losses, third-party litigation funding may be available to improve recovery economics.


Background: the Liquid Network exploit

The Liquid Network lets exchanges and trading firms move bitcoin between each other faster and more privately than on bitcoin's main network. It is run jointly by a group of companies, holding customers' bitcoin and issuing an equal number of Liquid tokens, called L-BTC. Each token can be redeemed for one real bitcoin.

On September 6, an attacker used a software flaw to create about 4,000 L-BTC tokens with nothing behind them, then redeemed them for about 3,996 real bitcoin, worth about $320 million (Blockstream). Within hours, the attacker posted a public message on the bitcoin blockchain: "we are whitehats. contact us on chain." In the industry, a "whitehat" is a hacker who looks for flaws in order to report them.

According to Blockstream, the attacker "returned 3,400 BTC … after several rounds of negotiations" on September 7, and "approximately 602 BTC remain outstanding," worth about $47 million. TRM Labs, a firm that traces crypto transactions, reports that the attacker appears to be keeping the balance as a reward (TRM Labs). Blockstream's report mentions no reward program, and nothing suggests it offered one.


Why the attacker has no right to keep $47 million

A bug bounty is a contract. The company offers a reward in advance, and a researcher earns it by doing what the offer requires. Without an offer, there is nothing to accept, and calling the funds a reward does not change who owns them.

The industry's own standard says the same. Under the SEAL Whitehat Safe Harbor, a company must adopt the terms before an incident. Rescuers must act during an attack already under way, return funds within 72 hours, and be "fully independent from the original exploit." The person who launched the attack cannot claim the reward for stopping it.

The Liquid attacker meets none of those conditions on the public record. The same party that caused the loss kept 15 percent and returned the rest only after negotiating. That looks less like a reward and more like the price of getting the rest back.

The Mango Markets precedent

The closest precedent involves the same amount. In 2022, Avraham Eisenberg took about $114 million from Mango Markets, a crypto trading platform, returned part of it, and kept about $47 million under a settlement its token holders approved by vote. Mango Labs then sued in the Southern District of New York to recover the $47 million, arguing the settlement was made under duress (Decrypt). If a formal settlement can be challenged that way, a one-sided claim with no agreement at all should be weaker still.

The criminal case is more cautionary. In May 2025, Judge Arun Subramanian vacated all of Eisenberg's convictions. He held that venue in Manhattan was improper, and that the wire fraud count failed because Mango had no terms of service, so Eisenberg made no false statement when he "borrowed" against assets whose price he had pushed up (TRM Labs). Prosecutors have appealed (DL News).

Why Liquid is a harder case for the attacker

Eisenberg used Mango the way it was built and let its rules do the rest. The Liquid attacker used a software flaw to create tokens backed by nothing and cashed them in for real bitcoin. That is much harder to describe as using a system on its own terms.

Civil claims such as conversion and unjust enrichment don't require proof of a false statement. Prosecutors have also moved beyond fraud theories. In February 2025, the Eastern District of New York charged Andean Medjedovic over two similar attacks with wire fraud, damaging a protected computer, attempted extortion and money laundering (CoinDesk). An attacker who returns funds only on condition of keeping a share should expect the extortion theory to come up.


How stolen crypto can be frozen

No one can freeze bitcoin on the bitcoin network itself, because there is no bank or issuer in the middle. A freeze works only when the funds reach a business that answers to a court: an exchange, a trading desk, a custodian or the issuer of a dollar-backed "stablecoin" if the attacker converts into one.

That makes recovery a race to the point where the attacker cashes out. TRM Labs has flagged the attacker's wallet addresses and is tracking the unreturned funds (TRM Labs). Compliant exchanges will notice a deposit from a flagged address, but without a court order most will hold funds only briefly.

Courts in the US and England have shown they will act against anonymous defendants:
  • New York. In LCX AG v. John Doe (N.Y. Sup. Ct. 2022), a Liechtenstein exchange obtained a freeze over stolen funds. The court let it serve the unknown defendant by sending a digital token, carrying a link to the court papers, to the wallet holding the funds (Morgan Lewis).
  • England. In D'Aloia v. Persons Unknown (2022), the High Court allowed service the same way. It also found that exchanges holding identifiable stolen crypto could arguably hold it on trust for the victim, so an exchange that ignores a freezing order risks liability of its own (White & Case).
The Liquid attacker has made service easier than usual by asking to be contacted through the blockchain and negotiating that way.
The practical steps are short:
  1. Trace and monitor every wallet the funds pass through.
  2. Have court papers ready before the funds move.
  3. Brief the exchanges most likely to receive the funds.
  4. Decide early on law enforcement. Criminal seizure can reach assets a civil order cannot, but it takes control of timing away from the victim. Blockstream's report does not mention law enforcement.

Negotiating with an attacker

Getting 85 percent back in about a day was a good result by any objective measure. Whether victims should take a deal like that will turn on individual circumstances. The legal question is what the victim gives up in return.
  • Don't concede ownership. Any message calling the retained funds a "bounty" or "reward" will likely be quoted back in a later lawsuit. Acknowledge receipt of what was returned without agreeing that the rest belongs to the attacker.
  • Make any release conditional. At a minimum, require disclosure of identity to counsel, a sanctions check, a statement that the attacker acted alone and automatic revival of claims if any of it proves false.
  • Check sanctions first. Letting an attacker keep funds is a transfer of value. OFAC's 2021 ransomware advisory says such violations "may result in civil penalties based on strict liability," and treats prompt reporting and cooperation with law enforcement as significant mitigating factors (Morgan Lewis). The two largest crypto thefts of April 2026 were both attributed to North Korea (CoinDesk). Nothing public links the Liquid attacker to a sanctioned party, but a victim can't know that without checking.
  • Keep the record. Save every message and transaction. A return made only "after several rounds of negotiations" is the best evidence that the balance was a price, not a reward.


The next dispute: who covers the shortfall

About 600 bitcoin of backing is still missing, and holders of Liquid tokens currently cannot redeem them for real bitcoin (Coinpaprika). Blockstream said on September 10 that the "1:1 LBTC to BTC peg will be covered," meaning each token will remain worth one bitcoin. (CryptoTimes) Until redemptions reopen, holders and business partners will ask what that pledge binds, and whom.

Blockstream's own timeline will shape those questions. An outside researcher reported one flaw on August 2. A fix reached 13 of the network's 15 operating servers by August 11 and was made public on September 1. Blockstream says that publication accidentally revealed a second flaw, which the attacker used five days later (Blockstream).

Claimants will ask predictable questions:
  • Disclosure timing. Was it reasonable to publish a fix before every operator had installed it and before the code was checked for related flaws?
  • The redemption path. The withdrawal went through SideSwap, one of the companies authorized to process redemptions. Blockstream says none of its security keys were compromised, but the company that processed the transaction will likely be named in any suit.
  • Duties of software developers. In Tulip Trading v. van der Laan [2023] EWCA Civ 83, the English Court of Appeal held it was arguable that bitcoin's software developers owe duties to users (Mayer Brown). The claim was later dropped, so the question remains open. A system run by known companies is an easier setting for that argument than bitcoin itself.

None of this means such claims would succeed. The answers depend on Liquid's terms, the agreements among the operating companies and the governing law. But those companies should settle among themselves how the shortfall is covered before a holder's lawyer raises it.

 
Daniel Podhaskie is Counsel at Whiteford, where he advises on cross-border litigation, asset recovery and enforcement, investigations and sanctions, and digital asset compliance and disputes. He has represented international clients in cross-border disputes, asset protection, regulatory investigations and transactions across the US, UK, Hong Kong, New Zealand, Australia, South Africa, France, the BVI and the Cayman Islands. His cryptocurrency and regulatory experience includes negotiating a global settlement with securities regulators in 35 states on behalf of a digital asset bank.
The information contained here is not intended to provide legal advice or opinion and should not be acted upon without consulting an attorney. Counsel should not be selected based on advertising materials, and we recommend that you conduct further investigation when seeking legal representation.