Liquid Recovers Majority of Stolen Bitcoin as Federation Members Coordinate Network Restart
Following a security incident that saw approximately 4,000 Bitcoin withdrawn, purported white-hat hackers have returned over 85% of the funds, though concerns remain about the actors' true intentions and unreturned collateral.
Substantial Return Restores Collateral Backing
A security incident on Liquid resulted in the withdrawal of roughly 4,000 Bitcoin from the federation wallet that previously secured approximately 4,200 BTC. In response to coordinated negotiations through onchain communications, purported white-hat actors transferred 3,400 Bitcoin—worth approximately $270 million—back to Liquid’s federation wallet, according to Blockstream and JAN3. This recovery represents about 85% of the initially withdrawn funds.
According to JAN3 CEO Samson Mow, a former Blockstream executive, the actors agreed to return the majority of stolen funds after Blockstream confirmed it had patched the vulnerable bridge nodes. Approximately 598 Bitcoin remains in the actors’ possession. Blockstream maintained ongoing communication with the actors through cryptographically signed messages embedded within Bitcoin transactions. The recovered funds are particularly important for Liquid’s operations, since the network issues L-BTC tokens backed by Bitcoin held in its federation wallet—meaning the return restores much of the collateral that was removed during the breach.
Addressing Vulnerabilities and Preparing Restart
The root cause of the security incident was traced to a vulnerability in Elements, the open-source software underpinning Liquid’s operations. The unauthorized withdrawal occurred through SideSwap’s Peg-out Authorization Key, though both SideSwap and Liquid clarified that the key mechanism itself was not compromised. Instead, a bug in the underlying Elements software enabled the breach.
Blockstream has deployed updated software to address the vulnerability, and federation members are coordinating a supervised network restart while implementing additional security improvements and resolving a chain split that emerged from the incident. According to Mow, Liquid will remain paused during these preparations. Users have been advised not to send Bitcoin to Liquid peg-in addresses until the restart is confirmed, though Mow noted that no other user action is required at this time.
Debate Over White-Hat Credentials
While the return of the majority of funds might suggest benevolent actors, skepticism has emerged regarding the white-hat characterization. Charles Guillemet, chief technology officer at Ledger, publicly questioned whether the actors truly deserve the white-hat label. Guillemet argued that if the remaining 598 Bitcoin represents a negotiated reward—facilitated through encrypted onchain communications—the arrangement more closely resembles extortion than traditional white-hat bug disclosure and remediation.
Neither Blockstream nor Liquid has publicly disclosed whether the outstanding Bitcoin constitutes a negotiated bounty or described specific repayment arrangements. When Cointelegraph contacted both entities for clarification, neither provided additional comment before publication. The incident highlights ongoing tensions between cryptocurrency infrastructure operators and security researchers regarding appropriate disclosure and compensation practices. For the broader crypto market, the Liquid incident demonstrates how vulnerabilities in major bridge protocols can rapidly undermine confidence in cross-chain infrastructure and underscores the importance of transparent communication during security events.
Source: Blockstream, via Cointelegraph. Not financial advice.