Blockstream's Liquid Network Hit by Nearly 4,000 BTC Exploit, Most Funds Returned
Blockstream's Liquid Network, a layer-two Bitcoin protocol, suffered a security incident over the weekend of 6 September when attackers drained nearly 4,000 BTC from its reserves. The attackers identified themselves as white hat hackers and used an OP_RETURN transaction, a feature that lets users attach public notes to Bitcoin payments, to announce themselves and request contact.
What followed was an unusual public negotiation conducted directly on the Bitcoin blockchain. Blockstream initially pointed the attackers to its security email and sent encrypted, PGP-signed messages. The attackers responded, and further encrypted exchanges are believed to have covered details of the vulnerability. Eventually, 3,400 BTC was returned to Blockstream's federation wallet, while the group kept 598.49 BTC.
The public nature of the exchange also attracted opportunistic activity, as unrelated users flooded the same wallet address with tiny transactions carrying their own messages, including meme coin promotions, money requests, laundering suggestions, and scam pitches. This has made it difficult to follow the legitimate negotiation using blockchain explorers.