The incident, which saw approximately 95% of the federation’s Bitcoin reserves siphoned off, began on Sept. 6 with a suspicious peg-out transaction. The perpetrators, who claim to be white-hat hackers, initiated a digital dialogue with Blockstream by embedding messages within Bitcoin OP_RETURN fields. According to Alex Thorn of Galaxy Research, these messages include encrypted data verifiable via PGP signatures, confirming that the individuals controlling the stolen assets are actively communicating with the network's developers.
In section Cryptocurrency
Liquid Network Hackers Demand Security Patch Before Returning 4,000 BTC
Unidentified actors who drained nearly 4,000 BTC from the Liquid Network have offered to return the majority of the funds, but only after Blockstream addresses the vulnerability that enabled the $320 million heist. The negotiation is currently playing out through a series of public, encrypted Bitcoin transactions.

Blockstream has not yet disclosed the specific nature of the flaw, though the attackers insist that every network node must be patched before they will initiate a return of the funds. In response to the breach, Liquid has disabled its bridge nodes and requested that exchanges halt L-BTC transactions. While the network remains effectively paused, no concrete timeline for a patch or a confirmed repayment has been established. The attackers have not clarified what portion of the 4,000 BTC they intend to retain as a bounty, leaving the ultimate recovery of the assets subject to the success of the ongoing security remediation.
Comments (0)
No comments yet. Be the first!