LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Liquid 'White Hats' Return $270M in Bitcoin as Network Prepares Restart

Cointelegraph · Ezra Reguerra

Following a security incident involving a SideSwap vulnerability that led to the withdrawal of approximately 4,000 BTC from Liquid Federation’s reserves, purported white-hat hackers returned 3,400 BTC (around $270 million) to the federation wallet. Blockstream confirmed that the vulnerability was patched and continues to engage with the actors regarding the remaining 598 BTC. Federation members are preparing for a coordinated network restart amid updated software deployment and enhanced security measures.

The Incident and Fund Return

On Sunday, hackers withdrew about 4,000 BTC from Liquid Federation’s reserves, totaling roughly 4,200 BTC. Subsequent onchain records show an exact return of 3,400 BTC to the federation’s wallet, representing approximately 85% of the stolen funds.

On Monday, JAN3 CEO and former Blockstream executive Samson Mow stated that the return happened after Blockstream confirmed that the affected bridge nodes had been patched. Approximately 598 BTC remain outstanding, with ongoing engagements between Blockstream and the actors.

Technical Details of the Breach

The original unauthorized withdrawal was executed through SideSwap’s Peg-out Authorization Key, though both Liquid and SideSwap asserted that the key itself was not compromised. The exploited L-BTC stemmed from a bug in Elements, the open-source software underpinning Liquid.

Blockstream reached out to the actors by embedding signed messages in Bitcoin transactions. Those actors identified themselves as white-hat hackers pledging to return the remaining funds once the vulnerability was fixed and every node installed the patch.

Liquid’s Restart Preparations and Industry Reactions

Liquid remains paused while Blockstream and federation members implement further security fixes, resolve a chain split, and prepare for a safe network restart. Users have been advised not to send Bitcoin to Liquid peg-in addresses until the restart is confirmed, though no other user action is required.

Ledger’s CTO Charles Guillemet questioned the white-hat label for the actors after the partial return. He suggested that if the roughly 600 BTC still held are a negotiated reward through encrypted onchain messages, this arrangement resembles extortion more than white-hat hacking.

Neither Blockstream nor Liquid publicly described the outstanding Bitcoin as a bounty or disclosed repayment terms. Cointelegraph sought comments but received none before publication.

Why it matters

This development is significant as it showcases a rare case where actors identifying as white-hat hackers partly return a large amount of stolen Bitcoin following the discovery of a vulnerability in the popular Liquid sidechain. It underscores the importance of continuous security monitoring and swift remediation in such critical infrastructure, while also highlighting the complex ethical and legal considerations within the crypto community. The partial fund recovery and preparations for a secure network restart may mitigate user risks and help restore confidence in Liquid as a Bitcoin sidechain.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗