Crypto· Bitcoin

Liquid ‘white hats’ return $270M in Bitcoin as network prepares restart

Actors claiming to be white-hat hackers returned 3,400 Bitcoin worth approximately $270 million to Liquid's federation wallet after withdrawing roughly $320 million from the sidechain's reserves during a security incident. The partial return came after Blockstream patched the affected bridge nodes and the actors confirmed they would restore most funds once the vulnerability was fixed, though about 598 BTC remains unaccounted for.

By AI NewsroomPublished about 4 hours agoUpdated about 4 hours ago5 views
Liquid ‘white hats’ return $270M in Bitcoin as network prepares restart

Why It Matters

The incident exposed a critical vulnerability in Liquid's infrastructure while demonstrating how major cryptocurrency platforms can negotiate security incidents through onchain communications. The situation highlights ongoing questions about whether such partial returns constitute legitimate white-hat behavior or represent a form of ransom, as the network prepares to restart operations.

Key Facts

  • Bitcoin returned: 3,400 BTC (approximately $270 million)
  • Bitcoin initially withdrawn: 4,000 BTC from roughly 4,200 BTC in reserves
  • Percentage recovered: 85% of the withdrawn funds
  • Outstanding Bitcoin: Approximately 598 BTC still held by the actors
  • Root cause: Bug in Elements, the open-source software underpinning Liquid

A security breach affecting Liquid, a Bitcoin sidechain, resulted in the unauthorized withdrawal of approximately $320 million in Bitcoin, but the actors involved returned the majority of the stolen funds after Blockstream deployed patches to address the underlying vulnerability. The incident unfolded over the weekend, with hackers gaining access to nearly all Bitcoin held in the Liquid Federation wallet. What distinguished this breach from typical theft attempts was the subsequent onchain negotiation between Blockstream officials and the attackers, who identified themselves as white-hat security researchers.

Blockstream engaged with the actors through signed messages embedded in Bitcoin transactions, and the actors agreed to return most of the withdrawn funds once the vulnerability was fixed and all federation nodes had installed the necessary patches. On Monday, approximately 3,400 Bitcoin was transferred back to the federation's wallet, restoring roughly 85% of the stolen reserves. JAN3 CEO Samson Mow confirmed the return and noted that about 598 BTC remains outstanding while Blockstream continues discussions with the actors regarding this remaining amount.

The vulnerability itself stemmed from a bug in Elements, the open-source software framework that underpins Liquid's operations. The attackers exploited this flaw to gain access through SideSwap's Peg-out Authorization Key, though both Liquid and SideSwap emphasized that the key itself had not been compromised. The return of the majority of funds significantly restores the Bitcoin backing for L-BTC, the sidechain's native asset, as the paused network prepares for a coordinated restart.

However, questions about the actors' true motives have emerged. Some observers, including Ledger's chief technology officer Charles Guillemet, have questioned whether the arrangement constitutes legitimate white-hat behavior or represents a form of extortion, particularly given that approximately 598 BTC remains under the actors' control. Neither Blockstream nor Liquid has publicly characterized this remaining amount as a negotiated bounty or disclosed specific repayment terms. Blockstream has advised users to refrain from sending Bitcoin to Liquid peg-in addresses until the network's full restart is confirmed.

Keep Reading