Cryptocurrency

Liquid Network Hackers Return $270M in Bitcoin After Security Fix

0

The security incident that drained roughly $320 million in Bitcoin from Liquid Network has taken an unexpected turn, with the actors behind the withdrawal returning around 3,400 BTC, worth approximately $270 million, to the network’s federation wallet.

The return came after Blockstream, the company behind Liquid, communicated with the actors through an on-chain message and said the affected bridge nodes had been patched. Around 600 BTC remains outstanding, leaving the incident unresolved despite the recovery of most of the funds.

The development adds another layer to an already unusual security incident, in which the individuals involved have been described as purported “white-hat hackers.”

Nearly 4,000 BTC Was Initially Withdrawn

The original incident involved approximately 4,000 BTC out of roughly 4,200 BTC held in Liquid’s federation wallet. Liquid subsequently halted new transactions while the network investigated the circumstances surrounding the withdrawals.

The funds were moved through SideSwap, a settlement platform authorized to facilitate withdrawals from Liquid. Importantly, Liquid said at the time that the cryptographic key used for the transactions had not been compromised.

Blockstream later attributed the incident to a software vulnerability affecting the infrastructure supporting Liquid rather than a straightforward private-key compromise. CoinDesk reported that the issue involved a bug in Elements, the open-source blockchain platform underlying Liquid.

That distinction is important because it suggests the incident may have resulted from a weakness in transaction or withdrawal logic rather than someone simply obtaining the federation wallet’s private credentials.

Attackers Return Most of the Funds

The return of approximately 3,400 BTC significantly changes the financial impact of the incident.

According to Decrypt, the funds were returned after Blockstream sent a signed message to the actors explaining that the relevant bridge nodes had been patched. The actors then transferred the Bitcoin back to the federation wallet.

However, the recovery does not mean the situation is over.

Nearly 600 BTC remains outside the federation wallet, and Liquid has not yet announced when normal operations will resume. The remaining funds therefore continue to represent both a financial and operational concern for the network.

White-Hat Claims Raise Questions

The decision by the attackers to return most of the Bitcoin has strengthened the possibility that they were attempting to demonstrate a vulnerability rather than permanently steal the assets.

Still, the characterization of the actors as white-hat hackers remains tentative.

In conventional cybersecurity, ethical hackers generally disclose vulnerabilities to affected organizations and give them an opportunity to fix the problem. Removing hundreds of millions of dollars in cryptocurrency without prior authorization creates a much more complicated situation, even if the funds are later returned.

The episode could therefore become an important case study for the crypto industry around how vulnerability researchers interact with decentralized financial infrastructure.

A Warning for Bitcoin Infrastructure

The Liquid incident also highlights a broader distinction between Bitcoin itself and infrastructure built around Bitcoin.

The Bitcoin blockchain was not itself compromised. Instead, the vulnerability affected a separate network designed to provide faster transactions and settlement connected to the Bitcoin ecosystem.

That distinction matters as crypto markets become increasingly dependent on sidechains, bridges, custodians and settlement networks.

As more institutional capital moves through these systems, vulnerabilities in supporting infrastructure can create losses that rival major exchange breaches.

For Liquid, recovering most of the Bitcoin is a significant positive development. But the remaining funds, the cause of the vulnerability and the timeline for restoring normal operations will determine how the market ultimately assesses the incident.

The episode also reinforces a lesson that has become increasingly important across digital assets: protecting blockchain infrastructure requires more than securing private keys. Software logic, transaction authorization and operational controls can be equally critical.

Hanwha Builds Tokenized Securities Platform on Avalanche Ahead of South Korea’s 2027 Rules

Previous article

Bitcoin ETFs Pull In Nearly $1 Billion as Institutional Demand Rebounds

Next article

You may also like

Comments

Comments are closed.