|
Getting your Trinity Audio player ready...
|
A tense standoff over $320 million in Bitcoin appears to be resolving, though not entirely on clean terms. Purported white-hat hackers have returned 3,400 BTC, worth roughly $270 million, to the Liquid Federation wallet after withdrawing nearly all of the sidechain’s reserves in a Sunday security incident — but hundreds of Bitcoin remain unaccounted for, raising questions about whether “white-hat” is the right label for what happened.
The episode has put Liquid, Blockstream’s Bitcoin sidechain, in an unusual position: recovering most of its stolen funds through negotiation rather than force, while still working through the fallout.
How the Funds Came Back
JAN3 CEO Samson Mow, a former Blockstream executive, said Monday that the return followed confirmation from Blockstream that the vulnerable bridge nodes had been patched. According to Mow, about 598 BTC is still outstanding, and Blockstream remains in contact with the parties responsible.
The original incident saw roughly 4,000 BTC withdrawn from the federation’s wallet, which held about 4,200 BTC at the time. Onchain records confirm that exactly 3,400 BTC was sent back to the federation’s address — meaning around 85% of the withdrawn funds have been restored. Since Liquid issues L-BTC backed one-to-one by Bitcoin held in the federation’s reserves, getting that Bitcoin back is critical to restoring the network’s backing before operations can safely resume.
Blockstream said it has deployed updated software and that federation members are preparing for a coordinated restart of the network.
What Actually Went Wrong
The withdrawal was processed through SideSwap’s Peg-out Authorization Key, though both Liquid and SideSwap have said the key itself wasn’t compromised. Instead, SideSwap attributes the incident to a bug in Elements, the open-source software that underpins the Liquid sidechain — a distinction that matters for understanding how the funds moved without a stolen credential being the direct cause.
To reach the people responsible, Blockstream turned to an unconventional communication method: signed messages embedded directly in Bitcoin transactions. Through that channel, the actors identified themselves as white hats and said they’d return the bulk of the funds once the vulnerability was fixed and every node had applied the patch — which appears to be exactly what played out.
Also Read: Ethereum Foundation Names Two “Must-Ship” Proposals for Hegotá Upgrade
Not Everyone Buys the White-Hat Framing
The partial return, with roughly 600 BTC still held back, has drawn skepticism. Ledger CTO Charles Guillemet pushed back on the white-hat characterization, arguing that if the retained Bitcoin represents compensation negotiated through encrypted onchain messages, the arrangement resembles extortion more than ethical disclosure.
Neither Blockstream nor Liquid has publicly confirmed the outstanding funds as a bounty or disclosed any specific terms of the arrangement, leaving the nature of the remaining 598 BTC unresolved.
Network Still Paused, Restart Pending
Mow said Liquid remains paused while Blockstream and federation members finish additional security fixes, resolve a chain split, and prepare for a safe restart. He urged users not to send Bitcoin to Liquid peg-in addresses until the restart is officially confirmed, though he noted no other action is required from users at this time.
The incident underscores a broader challenge facing Bitcoin sidechains and bridges: even when a vulnerability doesn’t involve a stolen key, the technical mechanics behind cross-chain custody can still expose massive sums to exploitation — and recovery may depend as much on negotiation as on code.
Disclaimer: The information in this article is for general purposes only and does not constitute financial advice. The author’s views are personal and may not reflect the views of Chain Affairs. Before making any investment decisions, you should always conduct your own research. Chain Affairs is not responsible for any financial losses.
