Summary

  • Blockstream is negotiating to recover approximately 598.5 BTC still missing following the Liquid Network exploit.
  • The hackers returned 3,400 BTC on Monday, leaving around 15% of the total amount unreturned.
  • A vulnerability in the software facilitated the exchange of unsupported L-BTC for reserve Bitcoin, according to Liquid.

On Tuesday, the Liquid Network announced that Blockstream, the company responsible for the Bitcoin sidechain, is actively engaged in discussions with the hackers who exploited the network, resulting in losses of about $320 million, in order to reclaim the stolen assets.

“Conversations between Blockstream and the parties involved are ongoing to secure the return of the remaining funds,” Liquid stated in a report shared on X.

Myriad: How high will Bitcoin go in September? Click here to make your prediction.

This negotiation follows Sunday’s withdrawal of roughly 4,000 BTC, which was made possible by a flaw in Liquid’s Elements software that allowed the creation of unsupported L-BTC tokens, which were then exchanged for reserve Bitcoin. The hackers returned 3,400 BTC on Monday, leaving about 600 BTC, equivalent to approximately $47 million, still outstanding.

Liquid did not disclose the specifics of the negotiations or an expected timeline for the recovery of the remaining Bitcoin.

According to Liquid, after the theft, the unidentified individuals converted the Bitcoin through SideSwap, a member of the Liquid Federation providing withdrawal services. The software's transaction validation process mistakenly accepted the unsupported tokens as legitimate prior to the withdrawal being executed.

“Due to a validation error occurring at the transaction level before the peg-out was initiated, both SideSwap’s node and the Liquid Network’s globally distributed functionary nodes recognized the L-BTC as valid,” the developers explained.

As a result of the exploit, Liquid’s reserves plummeted from about 4,205 BTC to just 197 BTC after the withdrawal and other transactions that took place before operations were suspended. Liquid assured users that USDT and other tokens issued by Liquid were not impacted by the vulnerability, but transactions were halted while the network was paused.

“The Liquid Federation functionaries were not compromised, and no private keys were exposed,” Liquid reassured users. “The peg-out mechanism, which authorizes withdrawals to whitelisted addresses, functioned as intended.”

During the incident, the perpetrators identified themselves as white-hat security researchers in a message on Bitcoin’s blockchain. However, skepticism about their intentions persisted, with some, including Ledger Chief Technology Officer Charles Guillemet, questioning the legitimacy of their claim after most of the funds were returned.

Guillemet remarked on X, “The ‘white hats’ still retain 600 BTC. If this was ever a negotiated reward under an encrypted contract signed on-chain, it appears more like extortion than white-hat hacking!”

In response to the attack, Liquid Network developers indicated that Blockstream is preparing an emergency update while the fix is under review, following a patch applied to its bridge nodes on Monday. Once the update is completed, network operators will implement further adjustments to restore normal operations and rectify the network’s state, including reversing the invalid withdrawal.

“Our immediate focus is on recovering the remaining funds and safely resuming normal network operations as swiftly as possible,” Liquid stated.

Daily Debrief Newsletter

Stay updated with the latest news stories, original features, podcasts, videos, and more.