NewsCryptoLiquid Network Recovers 3,400 Bitcoin After Exploit as Attackers Retain 15% of Stolen Funds

Liquid Network Recovers 3,400 Bitcoin After Exploit as Attackers Retain 15% of Stolen Funds

Author: CryptoMeter io·

Key Takeaways

  • Self-described white-hat hackers returned 3,400 BTC, worth roughly $268 million, to the Liquid Federation wallet on September 7, restoring about 85% of the stolen Bitcoin.
  • The attackers retained approximately 598.5 BTC, worth around $47 million, with no public agreement confirming it as a formal bug bounty.
  • The exploit stemmed from a vulnerability in Elements, the open-source software underlying Liquid, which allowed attackers to mint unbacked L-BTC and withdraw real Bitcoin from reserves.
  • Blockstream has patched the affected bridge nodes, but Liquid has not yet resumed peg-in and peg-out operations.
  • The majority recovery of stolen funds is rare for large bridge exploits, which historically — such as Ronin and Wormhole in 2022 — saw losses of hundreds of millions never returned.
Liquid Network Recovers 3,400 Bitcoin After Exploit as Attackers Retain 15% of Stolen Funds

The Liquid Network has recovered the majority of the Bitcoin removed in a major exploit, though nearly 600 BTC remains in the hands of the actors who carried out the attack.

On Sept. 7, the self-described white-hat hackers returned 3,400 BTC to the Liquid Federation wallet. At the time of the transaction, the recovered coins were worth approximately $268 million. The return restored roughly 85% of the Bitcoin taken from the network.

The attackers retained about 598.5 BTC, worth roughly $47 million. No public agreement confirms that amount as a formal bug bounty, although the retained funds have effectively become an unofficial reward.

The recovery followed an unusual negotiation conducted entirely through Bitcoin transactions. The attackers had stated they would return most of the funds after Blockstream patched the vulnerability affecting Liquid's infrastructure.

Liquid is a Bitcoin sidechain developed and maintained by Blockstream, and it is operated by a federation of member organizations rather than by miners as on the Bitcoin base chain. The network issues L-BTC, an asset pegged one-to-one to Bitcoin, which traders and exchanges use for faster settlement than the Bitcoin mainchain typically allows. That federated design means the security of the peg — the mechanism that swaps Bitcoin for L-BTC and back — is central to the network's function.

How the Liquid Exploit Worked

The incident began when roughly 4,000 BTC left Liquid's federation wallet through a peg-out transaction. Liquid stated that the breach did not involve compromised private keys.

Instead, the vulnerability appears to be linked to Elements, the open-source software underlying Liquid. The flaw reportedly allowed the attackers to mint L-BTC without sufficient Bitcoin backing, which they could then use to withdraw real Bitcoin from Liquid's reserves.

The incident also did not appear to compromise SideSwap's infrastructure. However, Liquid halted both peg-ins and peg-outs while operators investigated the vulnerability.

Cross-chain and sidechain bridges have historically been among the most targeted components of cryptocurrency infrastructure. Large bridge exploits in past years — such as the Ronin Network and Wormhole incidents of 2022 — each resulted in losses of several hundred million dollars, and most of those funds were never returned. The Liquid outcome, in which the majority of the stolen Bitcoin was recovered, is comparatively rare for attacks of this scale.

Liquid Faces a Difficult Restart

Blockstream has since patched the affected bridge nodes, enabling the attackers to return the majority of the funds. Nevertheless, Liquid has not immediately restored normal operations.

The remaining 598.5 BTC also raises questions about whether the attackers acted as legitimate white-hat researchers or simply negotiated their own compensation after exploiting the flaw. Formal bug bounty programs in the cryptocurrency industry typically pay researchers far smaller sums for responsibly disclosed vulnerabilities, and rewarding attackers who first extract funds can create incentives that security researchers have long warned about.

Liquid now faces the challenge of restarting its Bitcoin bridge while ensuring the authorization problem cannot be exploited again. Users and exchanges holding L-BTC will be watching for a full resumption of peg-ins and peg-outs, along with any post-incident technical report detailing the patched flaw. The recovery significantly reduces the financial damage, but the incident underscores the risks posed by vulnerabilities in systems responsible for securing large amounts of Bitcoin.