๐Ÿ“… Monday, 7 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Pembobol Liquid Tahan $320 Juta - Mereka Janji Kembalikan Sebagian Setelah Blockstream Patuhi Satu Syarat On-Chain

Liquid Exploiters Hold $320M - Promise Partial Refund After Blockstream Meets One On-Chain Condition

The unidentified actor in control of nearly 4,000 BTC from the Liquid Network has finally broken their silence. Through an OP_RETURN message on the Bitcoin network on Sept. 7, 2026, they offered to return the majority of the $320 million in funds, provided that Blockstream fixes the vulnerability on its end first.

The on-chain message was reconstructed by Alex Thorn from the Galaxy research team. The attacker explicitly asked developers to ensure that every node on the network has received the patch before they move the held assets. The initial exploit behind the incident had already sparked heated debate since the previous day.

On Sept. 6, a forced withdrawal of 3,996 BTC was confirmed in Bitcoin block 965,783. Alongside the transaction, the attacker left an initial message reading: “we are whitehats. contact us on chain”. The withdrawal immediately drained roughly 95% of the total reserves in Liquid’s federation wallet.

Vulnerability Outside the Primary Keys

Liquid’s development team reacted swiftly by shutting down their bridge node operations. Instructions were also sent to all partner crypto exchanges to temporarily suspend all deposit and withdrawal services for L-BTC tokens until further notice.

Liquid’s bridge system has relied on SideSwap’s Peg-out Authorization Key (PAK) as a security layer. Despite losses reaching hundreds of millions of dollars, operators stated there is no evidence that the key system itself was compromised. This reinforces indications that the hacker exploited a bug at a different layer.

The impact of the forced withdrawal remains isolated to the Bitcoin peg-out mechanism. Other digital assets operating within the Liquid ecosystem, from stablecoins to tokenized real-world assets (RWAs), remain unaffected and continue to function normally.

Conditions Still Pending

Liquid management referred to the perpetrators as “purported white-hat hackers.” That label was applied purely based on initial communications, but the attacker’s good intentions still leave numerous questions unanswered.

Follow-up messages from the attacker gave no details regarding the exact amount of the “majority” of funds to be returned. They also refused to disclose their identity and set no timeline for when the coin return would take place once the update is released.

As of writing, on-chain tracking shows no confirmed return transactions. Blockstream is now working to patch the network vulnerability as requested, while the public waits to see whether the hacker’s promise will materialize or end in empty negotiations.

Reported via crypto.news.

Previously: White Hat Drains 3,993 BTC from Liquid Network - But Bug Is in Software, Not Keys


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share