Liquid Network has recovered 3,400 BTC (about $268 million) after an exploit drained nearly 4,000 BTC (about $320 million) from its federation wallet. The attacker, who identified as a "white hat," retained 598.5 BTC (about $47 million) in an address linked to the withdrawal, representing roughly 15% of the stolen funds.
The incident stemmed from a range-proof verification cache bug in Elements, the open-source software powering Liquid nodes, which allowed the creation of unbacked L-BTC tokens. No private keys or federation wallets were compromised; instead, attackers exploited the issuance logic to generate valid-looking tokens that were then pegged out via SideSwap, draining 95% of Liquid’s Bitcoin reserves.
Liquid immediately froze network operations and disabled bridge nodes to secure the remaining assets. The network remained paused while node operators updated their bridge software and verified the security fixes.
Communication between the attacker and Blockstream occurred entirely on-chain via Bitcoin OP_RETURN messages.
The hacker consolidated the stolen Bitcoin into a single address and broadcasted an OP_RETURN message reading: "we are whitehats. contact us on chain."
Blockstream established formal contact around Bitcoin block 965,822 by embedding encrypted text and a PGP signature in an OP_RETURN transaction.
The attacker sent encrypted details of the exploit back to Blockstream, stating they would not return the funds until the bug was fully patched across all network nodes.
Blockstream replied with a PGP-signed OP_RETURN message confirming against their official key on record: "Bridge nodes are patched, safe to return the funds," after which the attacker broadcast the return transaction.
While the return mitigated immediate insolvency risks, Liquid Network operations remain paused to restore 1:1 backing, and the status of the retained $47 million remains unclear, with no formal bounty agreement published.
Liquid official communications referred to the actor as a "purported white-hat hacker." Security experts and crypto community members heavily debated labeling the hacker a true "white hat," noting that taking funds by force prior to negotiations is extortion rather than responsible disclosure.