A white-hat actor has returned 3,400 Bitcoin worth about $268 million to the Liquid Federation after exploiting a vulnerability. The actor still holds 598.5 BTC worth roughly $47 million.
CertiK reported the transfer on September 7 after the actor communicated with Blockstream about the incident. The returned Bitcoin represents most of the nearly 4,000 BTC involved in the exploit.
The actor asked Blockstream to fix the vulnerability before returning the Bitcoin. They also requested confirmation of the address that would receive the funds.
Blockstream later said it had patched the affected bridge nodes. In an on-chain message, the company told the actor, “Bridge nodes are patched, safe to return the funds.”
The actor subsequently transferred 3,400 BTC back to the federation after a series of on-chain messages between both sides.
The incident began on September 6, when nearly 4,000 BTC left a Liquid Federation wallet. Liquid linked the withdrawal to SideSwap’s Peg-out Authorization Key, or PAK.
Liquid said the PAK and other federation keys were not compromised. Blockstream later identified a bug in Elements, the open-source software that powers Liquid, as the source of the vulnerability.
CertiK said the remaining 598.5 BTC “could potentially be a bounty reward.” However, no formal agreement confirming a bounty has been disclosed.


