The purported white-hat hackers behind the roughly $320 million Liquid Network security incident are willing to return “most” of the nearly 4,000 BTC they withdrew.
The unusual pledge was made during an ongoing on-chain conversation between the unidentified actors and Blockstream, according to Galaxy Research head Alex Thorn.
A makeshift communication channel
The two sides have been communicating through Bitcoin OP_RETURN messages as well as PGP-encrypted text.
The episode began on Sunday after approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. It accounts for roughly 95% of the Bitcoin that had been pegged into the sidechain.
Liquid subsequently disabled its bridge nodes and paused the network.
Roughly $320 million worth of funds were then consolidated into a Bitcoin address alongside a message declaring: “we are whitehats. contact us on chain.”
Notably, Liquid itself has so far described those responsible only as “purported” white-hat hackers.
Patching the bug
According to Thorn’s reconstruction of the on-chain exchange, Blockstream attempted to establish contact at Bitcoin block 965,822 by sending 1,000 satoshis alongside an OP_RETURN message to alert the security team.
A subsequent transaction contained encrypted material addressed to the holder’s key together with a PGP signature. Thorn said the signature could be verified against Blockstream’s published public key.
The hackers later responded in block 965,869 by moving their own balance and directing 1,000 satoshis to the federation’s peg wallet.
Their accompanying message asked whether sending “most” of the funds back to the federation address would be acceptable.
The hackers told Blockstream that they would not return the Bitcoin until the damning vulnerability had been fixed across the network. “Please fix the bug first,” they said.
The hackers’ use of the word “most” leaves open the question of how much Bitcoin they intend to retain.
There is also no guarantee that they will follow through on the pledge.
Ledger Chief Technology Officer Charles Guillemet initially claimed that conventional white hats generally do not drain hundreds of millions of dollars from a bridge. He compared the situation with previous crypto exploits such as Ronin and Euler.
Guillemet later changed his tune after the hackers attempted to communicate.
Criminal groups do not typically make efforts to establish contact with their victims.
“There’s hope,” he wrote, arguing that these could be researched using powerful AI systems to locate the vulnerability without proper disclosure procedures.
For now, however, almost all of the Bitcoin remains under the hackers’ control.






Be the first to comment