Liquid Network: Whitehats Return 85% of Drained BTC, $47M Still At Large

A dramatic turn of events has unfolded in the Liquid Network saga, a Bitcoin sidechain that recently experienced an unusual outflow of nearly 4,000 BTC. The party responsible, identifying themselves as “whitehat hackers,” has returned a substantial 3,400 BTC to the Liquid Federation. This recovery, valued at approximately $269 million at the time of transfer, accounts for about 85% of the initially lost funds. However, a significant sum of approximately 598.5 BTC, worth around $47 million, remains under the party’s control, indicating the incident is not yet fully resolved.

The initial breach occurred on September 6th at 14:05 UTC, when a client initiated a 4,000 L-BTC peg-out service via SideSwap. According to SideSwap, their system processed the transaction as per standard procedures, destroying the L-BTC and obtaining a valid peg-out authorization. Just 23 minutes later, the Liquid Federation disbursed roughly 3,996 BTC to the designated address on the Bitcoin mainnet.

This event sent shockwaves through the market, as the Liquid Federation’s wallet, holding approximately 4,200 BTC, saw nearly 95% of its reserves—an estimated $320 million at BTC’s then-price of $80,000—drained in a single, anomalous transaction.

Rapid Reversal and the Whitehat Claim

Fortunately, the situation saw a swift reversal within 24 hours. Reports from The Block and on-chain analytics confirm that after Blockstream successfully patched the compromised bridge nodes, they communicated the fix to the responsible party via an on-chain Bitcoin message. Following this confirmation, a full 3,400 BTC was transferred back to the Liquid Federation’s address at Bitcoin block height 965,950.

Based on the party’s consolidated balance of approximately 3,998.5 BTC from the outflow, this return represents a substantial 85% recovery. What initially threatened to be an over $300 million asset deficit has largely been mitigated, yet critical questions persist.

The Unanswered Question: Why Keep 598.5 BTC?

The most pressing mystery now revolves around the remaining 598.5 BTC. On-chain records show that after returning the 3,400 BTC, this amount was retained by the party as “change” and redirected to their controlled address. At the time of the incident, this sum was valued at approximately $47.3 million.

The party initially identified themselves as “whitehats” through a Bitcoin OP_RETURN message, explicitly stating their intention to return funds only after Blockstream addressed the underlying vulnerability and confirmed the security of all nodes. Blockstream subsequently confirmed the fix with a PGP-signed on-chain message: “Bridge nodes are patched, safe to return the funds,” which preceded the 3,400 BTC return.

This sequence of events transforms what was initially perceived as a $320 million “hack” into an unprecedented on-chain negotiation for vulnerability disclosure and fund recovery. However, a crucial point of contention remains: there is no public evidence to suggest Blockstream agreed to allow the party to retain nearly 600 BTC as a bug bounty.

Charles Guillemet, CTO of Ledger, publicly raised concerns, questioning whether retaining such a significant sum without a pre-established, legitimate bug bounty agreement truly aligns with the definition of traditional “whitehat hacker” behavior, even after returning 85% of the funds.

Unmasking the True Vulnerability: Not a Private Key Compromise

Another pivotal revelation dispelled initial fears of private key theft. Both Liquid and SideSwap confirmed that the incident utilized SideSwap’s legitimate Peg-out Authorization Key (PAK), but neither this key nor any other Federation keys were compromised. This clarifies that the breach was not a direct attack on cryptographic security.

SideSwap’s disclosure, later corroborated by Blockstream, pinpointed the root cause: a critical vulnerability within Liquid’s underlying Elements software. This flaw allowed for the creation of “problematic L-BTC” that lacked corresponding BTC reserves. Crucially, from SideSwap’s perspective, these L-BTC appeared indistinguishable from legitimate L-BTC at the system level, leading their peg-out service to process the transaction as normal.

Liquid’s fundamental design dictates a 1:1 backing: 1 BTC locked into the Federation mints 1 L-BTC, and conversely, destroying 1 L-BTC releases 1 BTC from the Federation. Official Liquid documentation explicitly states this strict 1:1 ratio. The incident starkly exposed a critical flaw: a system that permits “L-BTC without corresponding BTC reserves” to enter the standard peg-out process can release real BTC, even when PAK and Federation signing keys remain perfectly secure. This architectural vulnerability presents a profound area for study in Bitcoin sidechain security.

Liquid Network’s Path to Full Recovery Remains Unclear

While the return of 3,400 BTC significantly reduced the financial shortfall, it does not signal the end of the incident. As of the latest public updates, Liquid has not confirmed whether the remaining 598.5 BTC will be returned, nor has it publicly acknowledged this sum as a mutually agreed-upon bug bounty.

In the aftermath, Liquid temporarily shut down its bridge nodes, prompting trading platforms to suspend L-BTC deposits and withdrawals. SideSwap’s swap, peg-in, and peg-out services are also on hold. There is currently no definitive timeline for the full restoration of these critical services.

The market is now closely monitoring three key developments: firstly, the fate of the remaining 598.5 BTC; secondly, Blockstream’s release of a comprehensive technical report on the Elements vulnerability; and thirdly, Liquid’s ability to re-establish and confirm the 1:1 reserve integrity of L-BTC before fully restoring its peg services.

From a purely financial perspective, the Liquid incident has seen a remarkable reversal. The initial outflow of approximately 4,000 BTC, valued at $320 million and representing nearly 95% of the Federation’s BTC reserves, has been largely contained with the recovery of 3,400 BTC, narrowing the unrecovered amount to about 598.5 BTC. However, the questions raised by this incident extend far beyond monetary losses.

The Liquid Network, a Bitcoin sidechain reliant on a Federation for its two-way BTC peg, has revealed a critical architectural flaw. This incident demonstrates that even with core BTC custody keys uncompromised, an upstream software validation vulnerability can lead to legitimate security mechanisms “correctly executing an incorrect transaction.” While the 3,400 BTC recovery addresses most of the asset deficit, it does not resolve this fundamental architectural issue.

The core question Liquid must answer is how a system with no compromised keys could still facilitate the release of nearly its entire Federation reserve in a single operation. This incident serves as a crucial case study for the entire blockchain ecosystem, emphasizing the complex interplay between cryptographic security and software logic in maintaining asset integrity.


Disclaimer: This article is for market information purposes only. All content and views are for reference only and do not constitute investment advice. They do not represent the views and positions of BlockBeats. Investors should make their own decisions and trades. The author and BlockBeats will not bear any responsibility for direct or indirect losses incurred by investors’ transactions.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these