Liquid Network Hackers Return $268 Million but Keep $47 Million Bounty
Self-described white-hats return the majority of stolen Bitcoin after Blockstream patches a critical bridge vulnerability.
Self-described white-hat hackers have returned the bulk of funds stolen in a massive breach of the Liquid Network's federation reserves. The partial recovery follows a critical security patch to the network's bridge nodes, which had been exploited to drain assets.
The attackers initially drained approximately 4,000 Bitcoin, valued at roughly $320 million, from the federation. Following the intervention by Blockstream, the attackers returned 3,400 BTC—approximately $268 million—to the federation's wallet. However, the hackers retained roughly 600 BTC, valued at approximately $47 million, which they have claimed as a "bug bounty."
The Bridge Vulnerability
The Liquid Network, a Bitcoin sidechain developed by Blockstream, utilizes a federation of nodes to manage its reserves. The breach specifically targeted the network's bridge, the mechanism that allows assets to move between the Bitcoin mainnet and the sidechain. In response to the drainage, Blockstream deployed a patch to the bridge nodes to close the security hole and prevent further losses.
Industry Implications
This incident underscores the systemic risk associated with blockchain bridges, which continue to be high-value targets for exploits due to their role as liquidity hubs. While the return of 85% of the funds suggests a cooperative resolution, the retention of $47 million highlights the precarious nature of "white-hat" claims. The event demonstrates that even with rapid patching, the financial fallout from bridge vulnerabilities can be substantial and permanent.
Current Status
While the majority of the funds have been recovered, the Liquid Network continues to manage the aftermath of the exploit. Observers are monitoring the remaining 600 BTC held by the attackers to see if further negotiations occur or if the funds are moved into mixers. The incident serves as a stark reminder for sidechain operators to harden bridge security against sophisticated drainage attacks. The scale of this exploit highlights the ongoing tension between security researchers and the protocols they test, as the line between a legitimate bug bounty and a theft remains thin when millions of dollars are at stake.