Crypto

Liquid attackers offer to return most of 4,000 BTC


On Sept. 7, unidentified actors controlling nearly 4,000 BTC taken from Liquid Network offered to return “most” of the funds after Blockstream fixes the vulnerability behind the estimated $320 million incident.

Summary

  • Nearly 4,000 BTC left Liquid’s federation wallet, representing approximately 95% of its reported Bitcoin reserves.
  • The unidentified actors offered to return most funds after Blockstream patches the undisclosed network vulnerability.
  • Bitcoin OP_RETURN messages and PGP signatures created a publicly verifiable communication channel between both parties.
  • Liquid disabled bridge nodes and asked exchanges to suspend L-BTC deposits and withdrawals during investigation.
  • No confirmed repayment, public patch or network reopening had occurred when this article was prepared.

The actors communicated their offer through Bitcoin transactions carrying OP_RETURN messages, according to a reconstruction published by Galaxy Research head Alex Thorn. They asked whether returning “most” of the Bitcoin to the federation’s address would be acceptable.

A later message told Blockstream to “fix the bug first” and ensure every node received the patch. The actors claimed the chain remained exposed under its latest software version and promised to transfer the money after confirming the repair.

That promise remains unverified. The actors did not define how much “most” represents, disclose their identities or provide a deadline. No confirmed return transaction had appeared when this article was prepared.

On-chain messages authenticate the negotiation

Blockstream initiated contact at Bitcoin block 965,822 by sending 1,000 satoshis with a message directing the recipient to its security team. Another transaction contained encrypted material and a detached signature verifiable against Blockstream’s published PGP key.

At block 965,869, the actors sent 1,000 satoshis to the federation’s peg address and asked about returning most of the funds. They provided their patch demand six blocks later. The messages establish that someone controlling the relevant Bitcoin could respond to Blockstream. They do not independently prove the actors’ motives.

The incident began with a peg-out of approximately 3,996 BTC. The corresponding Bitcoin transaction was confirmed in block 965,783 on Sept. 6. A separate transaction carried the initial claim: “we are whitehats. contact us on chain.”

The 4,000 BTC withdrawal exposed Liquid’s peg

Liquid confirmed that approximately 4,000 BTC had left its federation wallet. It described those responsible as “purported white-hat hackers,” preserving uncertainty around their status.

The network said the withdrawal used SideSwap’s Peg-out Authorization Key, or PAK. However, it said there was no evidence that the key itself was compromised. Liquid has not publicly explained the underlying vulnerability or released a technical postmortem.

Liquid operates as a Bitcoin sidechain whose users lock BTC and receive L-BTC for activity on the network. The federation holds the underlying Bitcoin and authorizes withdrawals back to the base layer. The transfer reportedly removed about 95% of the wallet’s Bitcoin.

Liquid disabled its bridge nodes and asked exchanges to suspend L-BTC deposits and withdrawals. It said other issued assets, including stablecoins and real-world assets, were not directly removed. The sidechain remained effectively paused while the investigation continued.

The episode adds another large loss to a year dominated by infrastructure failures. As crypto.news reported, crypto protocols lost at least $1.3 billion to hacks during the first eight months of 2026. In related coverage, an examination of cross-chain bridge security explained how concentrated custody and authorization systems can create large points of failure.

Blockstream must patch the network before any restart

Blockstream’s immediate task is to identify the flaw, prepare a patch and distribute it across the federation. The actors specifically demanded that every node be updated before repayment. Blockstream has not announced a patch version or reopening time.

A return can only be treated as confirmed after the Bitcoin moves to an address controlled by the federation. Even then, the amount retained by the actors and any proposed bounty would require disclosure.

Liquid must also account for the remaining reserves, explain how the peg-out bypassed normal controls and specify how L-BTC redemptions will resume. A technical postmortem would be needed to show whether the problem involved software, authorization logic, federation operations or another part of the withdrawal process.

Until those steps occur, the repayment remains a conditional promise and the “white hat” description remains disputed.




Source link

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button