Liquid Network Hack Takes a Twist: Hackers Offer to Return $320 Million
0
0

The people holding roughly $320 million in bitcoin drained from Blockstream’s Liquid Network say they will return most of the funds — but only after the vulnerability that enabled the exploit is fixed. The negotiation is unfolding publicly, through messages embedded in Bitcoin transactions.
Roughly 4,000 bitcoin were withdrawn from Liquid’s federation wallet on September 6, leaving the network facing a software vulnerability and a $320 million hole in its reserves.
Now, the two sides are communicating through small Bitcoin transactions carrying messages that are permanently recorded on-chain.
On September 6, roughly 4,000 of the approximately 4,200 bitcoin backing Blockstream’s Liquid Network, a Bitcoin-based payments and settlement network, were withdrawn from its federation wallet in a single transfer worth about $320 million at the time by “purported white-hat hackers,” according to the company.
Blockstream attributed the incident to a software bug in Elements, the software underlying Liquid. The funds moved through SideSwap, an approved Liquid trading platform, which reportedly could not distinguish between legitimate and exploit-created coins.
Liquid subsequently halted new transactions while federation members work to resolve the vulnerability and restore normal operations.
Liquid Hackers Negotiate the Bitcoin Return on the Blockchain
The most unusual part of the incident is what happened next: the alleged white-hat hackers and Blockstream began communicating publicly through OP_RETURN messages embedded in the blockchain, including a discussion over whether returning “most” of the funds would be acceptable.
A white-hat hacker is an ethical hacker who exploits a flaw in a protected system before malicious actors can. They typically exploit a flaw, move the money and seek a fee to return it.
In the Liquid case, the people behind the withdrawal stated that they would return the funds after Liquid fixes the vulnerability.
The messages provide a public record of the exchange between the two sides.
Using tiny "dust" transactions carrying OP_RETURN messages, the two sides have spent the past day negotiating the return of the funds in full public view.
“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” the message stated.
The episode has echoes of the 2024 Ronin Bridge incident, when a white-hat MEV searcher exploited a vulnerability and withdrew about 4,000 ETH and $2 million in USDC, worth roughly $12 million at the time.
Ronin stopped the bridge, contacted the operator, and the funds were returned. Ronin said it was negotiating with the actor because they appeared to be white hats acting in good faith. The white hat received a $500,000 bounty.
The process was much faster: the incident occurred, the bridge was stopped, Ronin publicly acknowledged the issue, and the funds were returned about 80 minutes later.
The Liquid case is nearly 27 times larger — and the people holding the funds have made their return conditional on Blockstream fixing the vulnerability and patching the network, while the funds remain in their hands.
The incident has put Liquid’s $320 million reserve problem and its software vulnerability on the same clock.
The network has been paused, and exchanges have suspended L-BTC deposits and withdrawals while the investigation continues.
The negotiation is also unfolding through a channel that is public, timestamped and cryptographically verifiable. The identity of the fund holder, however, remains anonymous.
Explore DailyCoin’s top crypto news right now:
SoFi Taps Kraken to Power Crypto Trading Behind Its Banking App
Japan’s 10Y Bond Yield Hits 3%. Why Bitcoin Should Pay Attention
0
0
Securely connect the portfolio you’re using to start.





