Liquid Network hacker returns 3,400 Bitcoins, keeps $47 million worth of Bitcoins as bonus

📅 2026-09-08

Abstract:

Yesterday, a major security incident occurred in the Bitcoin side chain Liquid Network and its services were completely suspended. An attacker claiming to be a white hat hacker discovered a software vulnerability at the bottom of the network and transferred 4,000 Bitcoins from the wallet. These Bitcoins account for 95% of Liquid Network’s reserves, but the attacker who launched the attack claims to be a white hat hacker who will return the stolen Bitcoins.

Hackers returned 85% of stolen funds after vulnerability fix:

The latest development in this security incident is that the attacker returned 3,400 Bitcoins after Liquid Network fixed the vulnerability, while the attacker still retained 598.5 Bitcoins worth $47 million. There is currently no public information to prove that this fund is a bug bounty determined by Liquid Network after formal negotiations with the attackers, so it is not accurate to call the $47 million in Bitcoin a bounty.

The proportion of Bitcoins returned by the hacker to Liquid Network is about 85%, which means that the hacker retains 15% of the Bitcoins. The hacker may be preparing to use this 15% of Bitcoins as his own vulnerability reward, but it will ultimately have to be confirmed by Liquid Network. If no agreement is reached, these Bitcoins may still be frozen on the chain.

Soldier first, etiquette later to prevent white prostitution?

This kind of practice of transferring huge amounts of money first and then reminding the platform to fix the vulnerability is not common, especially when the attacker claims to be a white hat hacker. In the field of cryptocurrency, various types of cyber security incidents involving attacks and theft of cryptocurrency occur in an endless stream. Even so, platforms are not very enthusiastic about paying bug bounties.

This incident is most likely because the attacker is worried that he will not receive reasonable compensation for reporting the vulnerability. After all, the specific bounty after the vulnerability is repaired depends entirely on the platform. Now, if you hold 4,000 Bitcoins, you are eligible to negotiate with the platform. If you do not agree, the Bitcoin will be shelved, which is a disguised form of forcing the platform to give a satisfactory bounty.

Of course, if the attacker does not return most of the Bitcoins, it is pure hacking. These Bitcoins can be frozen and the platform can seek help from law enforcement agencies. This is not worth the loss for the attacker, so it is indeed a wise approach to force the platform to reach a bonus agreement first with force and then with courtesy.

Related articles:

Bitcoin blockchain Liquid was hacked and lost US$320 million, and about 4,000 Bitcoins were stolen

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet