mt logoMyToken
ETH Gas
Tiếng việt

Liquid Network Attacker Returns 85% of Stolen $320 Million in Bitcoin After Blockstream Patches Bug

sưu tầmcollect
đăng lạishare
Liquid Network Attacker Returns 85% of Stolen $320 Million in Bitcoin After Blockstream Patches Bug

An attacker who withdrew roughly 4,000 BTC, worth about $320 million at the time, from Blockstream's Liquid Network federation wallet on September 6 has returned 3,400 BTC of it after the company patched the underlying bug, according to Blockstream's official status page . The attacker kept 598.5 BTC, worth about $47 million at current prices, or roughly 15% of the total.

Following the recent incident affecting the Liquid Network and the movement of funds, Blockstream, as Liquid’s technical provider, and the Liquid Federation have been working diligently to resolve the ongoing situation and ensure the return of assets.

Updated software has been…

— Blockstream (@Blockstream) September 8, 2026

The withdrawal went through SideSwap's Peg-out Authorization Key, one of several keys federation members hold to move funds off the sidechain. Blockstream said on its status page that the key itself "was not compromised, nor were any others," meaning the attacker did not steal a private key but instead exploited a flaw in how Liquid's federation validated peg-out requests, letting 11 of the required signatures push through a transaction that should have needed stronger checks. Other assets on Liquid, including USDT, DePix and various real-world-asset tokens, were unaffected.

Blockstream disabled its public bridge nodes within hours, pausing the sidechain and prompting exchanges to suspend LBTC deposits and withdrawals while federation members investigated. The attacker communicated through OP_RETURN messages embedded in Bitcoin transactions, first writing "we are whitehats. contact us on chain," according to on-chain messages reported by The Block . In one exchange, the attacker offered to send back "most" of the funds on condition that Blockstream fix the bug and patch every node first. Blockstream agreed, replying: "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."

On September 7 at 09:19:46 UTC, Blockstream posted a PGP-signed message confirming its bridge nodes were patched and it was "safe to return the funds." The attacker sent back 3,400 BTC shortly after.

The root cause traces to a validation bug in Elements, the open-source Bitcoin fork Blockstream maintains and that underpins Liquid's sidechain software, according to reporting from Protos . A commit posted to the Elements repository on September 1, five days before the incident, addressed a case where "a dynafed header with a mismatched height could be accepted," though Blockstream has not confirmed this specific commit was the vulnerability exploited. Reporting on the incident has also noted that Liquid's functionary codebase, the software federation members run to process peg-ins and peg-outs, had not been updated in more than two years before the exploit.

Blockstream has not said when it expects to fully restore normal Liquid Network operations, and the 598.5 BTC retained by the attacker remains unaccounted for beyond speculation, reported by CryptoTimes , that it may function as an informal bounty.

➢ Stay ahead of the curve. Join Blockhead on Telegram today for all the latest in crypto.
+ Follow Blockhead on Google News
Tuyên bố từ chối trách nhiệm: Bản quyền của bài viết này thuộc về tác giả gốc và không đại diện cho MyToken(www.mytokencap.com)Ý kiến ​​và vị trí; vui lòng liên hệ với chúng tôi nếu bạn có thắc mắc về nội dung
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
https://t.me/mytokenGroup
Đọc liên quan