Liquid Network has recovered most of the Bitcoin removed during a major exploit, but nearly 600 BTC remains with the actors who carried out the attack.
The self-described white-hat hackers returned 3,400 BTC to the Liquid Federation wallet on Sept. 7. The recovered coins were worth about $268 million at the time of the transaction. The return restored roughly 85% of the Bitcoin taken from the network.
The attackers retained about 598.5 BTC, worth roughly $47 million. No public agreement confirms that amount as a formal bug bounty, although the retained funds have effectively become an unofficial reward.
The recovery followed an unusual negotiation conducted through Bitcoin transactions. The attackers had said they would return most of the funds after Blockstream patched the vulnerability affecting Liquid’s infrastructure.
How the Liquid Exploit Worked
The incident began when roughly 4,000 BTC left Liquid’s federation wallet through a peg-out transaction. Liquid said the breach did not involve compromised private keys.
Instead, the vulnerability appears linked to Elements, the open-source software underlying Liquid. The flaw reportedly allowed attackers to create L-BTC without sufficient Bitcoin backing. They could then use those tokens to withdraw real Bitcoin from Liquid’s reserves.
The incident also did not appear to compromise SideSwap’s infrastructure. However, Liquid halted peg-ins and peg-outs while operators investigated the vulnerability.
Liquid Faces a Difficult Restart
Blockstream has patched the affected bridge nodes, allowing the attackers to return the majority of the funds. However, Liquid has not immediately restored normal operations.
The remaining 598.5 BTC also leaves questions about whether the attackers acted as legitimate white-hat researchers or simply negotiated their own compensation after exploiting the flaw.
Liquid now faces the task of restarting its Bitcoin bridge while ensuring the authorization problem cannot be exploited again. The recovery significantly reduces the financial damage, but the incident highlights the risks of vulnerabilities in systems responsible for securing large amounts of Bitcoin.