Hackers Behind $320M Liquid Network Withdrawal Signal Willingness to Return Funds
An unidentified group that withdrew roughly 4,000 BTC (about $320 million) from Blockstream's Liquid Federation wallet, accounting for around 95% of the Bitcoin pegged into the sidechain, is now negotiating a partial return of the funds. The incident began on Sunday, prompting Liquid to disable its bridge nodes and pause the network. The attackers consolidated the funds into a single address with a message identifying themselves as 'whitehats' and inviting contact.
According to Galaxy Research's Alex Thorn, Blockstream and the actors have since exchanged verified PGP-signed messages via Bitcoin OP_RETURN transactions. The attackers indicated they would return 'most' of the funds, but only after the underlying vulnerability that allowed the withdrawal is fixed. It remains unclear how much Bitcoin they intend to keep, and there is no guarantee the pledge will be honoured.
Security commentators have been divided on the actors' intentions. Ledger's CTO Charles Guillemet initially compared the incident to malicious bridge exploits like Ronin and Euler, but later softened his stance after the attackers engaged in direct communication, a behaviour unusual for criminal groups.