top of page

Liquid Network's $320 million vulnerability: "White Hat" Hacker unexpectedly returns most of the Bitcoin

Sep 9
3 min read

Recently, Liquid Network went through a turbulent ordeal after suffering a loss of approximately 4,000 Bitcoins (worth around $320 million at the time of the incident). However, the attack concluded with an unexpected turn of events: the attacker claimed to be a "white hat hacker" (well-intentioned security experts) and transferred back 85% of the funds, equivalent to 3,400 BTC, immediately after the developer completed the incident remediation.

liquid-network
Liquid Network, a blockchain linked to Bitcoin

A vulnerability "dormant" for over two years on Liquid Network

The incident began on September 6, 2026, when an anonymous individual discovered a weakness in the withdrawal transaction verification (peg-out) process on the Liquid sidechain. Notably, the hacker did not steal any private security keys. Instead, they exploited a software flaw deep within the Elements open-source codebase – the core platform powering the network, maintained by Blockstream.

According to Blockstream, this vulnerability had existed undetected for over two years. The bug inadvertently allowed peg-out transactions to be approved with only 11 out of 15 signature attestations, enabling the hacker to easily bypass the most stringent security controls. Fortunately, other digital assets on the network, such as USDT or Real-World Asset tokens, remained secure and unaffected.

An unusual negotiation on the blockchain

Upon detecting the anomaly, Blockstream immediately disabled public gateways, paused the network, and requested exchanges to halt L-BTC deposits and withdrawals to conduct an investigation.

At this point, a fascinating dialogue unfolded directly in cyberspace. Through messages embedded in Bitcoin transactions, the attacker proactively initiated contact with the message: "We are white hat hackers. Contact us on-chain." The group presented a clear condition: Blockstream had to thoroughly patch the vulnerability and update all nodes, after which they would guarantee a safe return of the funds.

The Blockstream team agreed to the arrangement. By the morning of September 7, the company published a cryptographically signed announcement confirming that the entire system had been patched and was "ready to receive the funds." Without hesitation, the hacker kept their promise and returned 3,400 Bitcoins shortly after.

The $47 million "bounty" and current situation

Despite returning the majority of the funds, the attacker chose to retain 598.5 BTC (valued at approximately $47 million at current prices), representing 15% of the original sum. While no official statement has been released regarding this figure, many tech industry observers view it as an informal "bug bounty" self-awarded by the hacker.

Currently, Blockstream and its alliance partners operating the network are working diligently to fully resolve the incident. Their primary focus is resolving the chain split and completely restoring the reserve backing ratio for L-BTC. While awaiting system stabilization, experts strongly advise users against transferring Bitcoin to Liquid Network deposit addresses.

blockstream-liquid-network
Statement from Blockstream after the incident

Proactive system protection advice for businesses

The Liquid Network incident serves as another wake-up call for tech platforms regarding the critical importance of routinely auditing and updating legacy codebase. Although the network was fortunate enough to encounter well-intentioned hackers this time, the $47 million loss is stark proof of a harsh reality: in the cryptocurrency world, any oversight can carry a heavy price tag.

To proactively identify and remediate cybersecurity vulnerabilities before they are exploited by threat actors, periodic penetration testing is a strategic step for every enterprise. IPSIP Vietnam's Pentest service applies controlled testing practices in accordance with international OWASP WSTG standards, holding ISO/IEC 27001:2022 and SOC 2 Type II certifications. Our team of experts goes beyond uncovering vulnerabilities by delivering detailed technical reports, actionable remediation roadmap consulting, and complimentary retesting support.


Refer to: BLOCKHEAD

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page