Liquid attacker says most of the 4,000 BTC could return after a patch
Onchain messages reportedly show the actor behind Liquid’s $320 million withdrawal offering to return most of the bitcoin after Blockstream fixes the vulnerability and updates every node; no funds have been returned yet.
By The Third AnglePublished 4 min read
A pledge to return compromised bitcoin is not the same as a completed recovery. Photo: Unsplash · Unsplash License
A conditional recovery offer
The actor who moved roughly 4,000 BTC from Liquid’s federation wallet says most of the funds could be returned after the network vulnerability is fixed. Cointelegraph reported that Blockstream and the actor exchanged signed onchain messages and that the proposed return depends on patching the Elements software across Liquid nodes.
The reported communication is unusually specific. A small test transfer and OP_RETURN messages reportedly established a channel, while encrypted material was sent to Blockstream for its security team to review. The messages describe a future return of “most” of the bitcoin, not a promise to restore every coin or an admission that the transfer was authorized.
The important distinction is a recovery pledge is not a recovery. The public record still shows the original movement, and there is no confirmed return transaction in the reporting reviewed for this cycle. Liquid has also not published a completed incident report identifying the bug or confirming that the network is safe to resume.
Why the patch is the next test
Liquid’s operators must now coordinate a fix for the Elements-based software and ensure that federation members and other nodes are running compatible versions. The Block’s earlier report said the sidechain was paused after the withdrawal while Blockstream worked to contact the party involved.
That creates a difficult sequencing problem. Publishing technical details too early could help a second attacker, but delaying a fix leaves users exposed and prolongs the halt on L-BTC activity. A credible resolution should include a signed technical explanation, affected software versions, a node-upgrade status, and an auditable accounting of the reserve wallet.
The “white hat” label also remains provisional. The actor may have disclosed a real vulnerability and may intend to return funds, but the withdrawal was still unauthorized from users’ perspective unless and until Liquid confirms the facts and the assets are restored. Do not count promised funds as recovered until blockchain data shows them back under federation control.
For users, the practical watch list is narrow: whether Liquid resumes transfers, whether the patch is independently reviewed, whether the reserve balance is reconciled onchain and whether most of the bitcoin actually returns. The incident is confined to Liquid’s federated sidechain and its bridge assumptions; it does not indicate that Bitcoin’s base layer was compromised.