Hackers linked to the recent Liquid Network incident have returned around 3,400 Bitcoin after taking nearly 4,000 BTC from the network’s federation wallet. The stolen Bitcoin was worth about $320 million when the attack happened on September 6. Liquid said the withdrawal was processed through SideSwap, but its authorization key was not compromised. The incident was later traced to a software vulnerability in Elements, the open-source technology that powers the Liquid Network and handles important parts of its Bitcoin sidechain operations.
The attackers were described by Liquid as purported white-hat hackers and later communicated with Blockstream through Bitcoin transaction messages and encrypted communication. They said the software problem needed to be fixed before the funds could safely be returned. Blockstream subsequently confirmed that the affected bridge nodes had been patched. After that confirmation, approximately 3,400 BTC were sent back to the Liquid Federation wallet, recovering roughly 85% of the Bitcoin that had been taken during the incident.
The remaining amount is still a major concern. Around 598.5 BTC, worth approximately $47 million based on the reported value, has not been returned. The attackers have kept those coins while discussions over the remaining funds continue. Their decision to retain such a large amount has also raised questions about whether they should truly be considered white-hat hackers. Security experts have pointed out that keeping a portion of funds after exploiting a system makes the situation more complicated than a normal responsible security disclosure.
The main problem was not a stolen private key but a flaw in the Elements software. The vulnerability allowed attackers to create L-BTC that was not properly backed by real Bitcoin and then use the normal peg-out process to obtain actual BTC. Because the fraudulent L-BTC could pass through the system as if it were legitimate, SideSwap processed the transaction using its normal authorization process. SideSwap has said that neither its systems nor its peg-out authorization key were compromised during the incident.
Following the attack, Liquid paused network activity and disabled its bridge nodes while the security issue was investigated and fixed. Exchanges supporting L-BTC were also asked to suspend deposits and withdrawals. The incident affected the Liquid sidechain, rather than Bitcoin’s main blockchain itself. The recovery of 3,400 BTC means most of the funds have now been returned, but the network remains under scrutiny while the remaining Bitcoin and the wider security implications of the vulnerability are being addressed.
The incident highlights an important security lesson for blockchain networks: protecting private keys alone is not enough. Software vulnerabilities can sometimes allow attackers to make invalid transactions appear legitimate before those transactions reach the systems controlling real assets. In the Liquid case, the federation’s keys were reportedly not stolen, yet the software flaw still resulted in billions of dollars worth of Bitcoin being moved. With about $47 million still outstanding, attention now remains on whether the remaining Bitcoin will be returned and when Liquid can safely resume normal operations.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news