Key facts
- Blockstream is negotiating with hackers to recover remaining stolen funds from the Liquid Network exploit.
- Approximately 600 BTC, valued at $47 million, is still missing after the exploit.
- A software flaw allowed the creation of unbacked L-BTC tokens, which were then exchanged for reserve Bitcoin.
- The hackers returned 3,400 BTC out of an initial 4,000 BTC withdrawal.
- Liquid Network is preparing an emergency software update to address the vulnerability.
Blockstream, the company behind the Liquid Network, is engaged in discussions with the individuals responsible for a recent exploit that resulted in the loss of approximately 4,000 BTC. Following the incident, where a software flaw allowed for the creation of unbacked L-BTC tokens exchanged for reserve Bitcoin, the hackers returned 3,400 BTC. However, about 600 BTC, valued at roughly $47 million, remains unreturned. Liquid stated that the vulnerability occurred at the transaction level before withdrawals were initiated, leading to the acceptance of invalid tokens by both SideSwap's node and the Liquid Network's functionary nodes. The network's reserve significantly decreased following the exploit. Liquid assured users that its functionaries were not hacked and no private keys were compromised. The individuals involved identified themselves as white-hat security researchers, a claim met with skepticism by some, including Ledger's CTO, who suggested it could be extortion. Liquid Network developers are preparing an emergency software update to patch the vulnerability and restore normal operations safely.
