Following Blockstream reported the bridge nodes were patched and the funds are safely restored, the actors shifted 3,400 BTC back to the federation address. The 598.5 BTC was maintained and no on-chain messages denoted the outstanding 15% as agreed payment.
A common wallet hack demonstrating stolen private keys, the case did not exploit Liquid’s federation keys. Alternately, the security flaw originated from Elements, the Bitcoin Core software powering Liquid nodes
The Verification Cache Bug
The evaluation suggests the case arose from a verification cache bug in Elements, enabling hackers to mint unbacked L-BTC. The network authorized invalid tokens, which were exchanged for real bitcoin from Liquid’s reserves.
The hackers carried out a 2.5 BTC test transaction prior to sending 4,000 L-BTC to federation key. The federation key processed the request and submitted the payment request, following which Liquid’s federation shifted 3,996 BTC to the assigned address.
Liquid’s federation signers managed as intended when processing an authorized withdrawal request. The concern came earlier, when unsupported L-BTC was launched into the network, making the case an issuance failure than a security breach.
White Hat Issues
The actors leveraged Bitcoin OP_RETURN messages to processed publicly, initially determining as white hats and requesting on-chain contact. Blockstream responded with PGP signed messages, following which the hacker authorized to return the funds once the network has been patched.
In contrast, the white hat is still a concern. Charles Guillemet, Ledger CTO, objected the initiative of taking funds prior to negotiating. He further suggests the actors may have been inexperienced researchers. Liquid has cited to more carefully worded as purported white hat hackers.
The Ongoing Recovery
The 3,400 BTC helped alleviate concerns over Liquid’s reserves. However, the network has not totally recovered. Liquid is still paused, bridge nodes are still deactivated, and L-BTC deposits and withdrawal on centralized exchanges are currently suspended. Additionally, Liquid assets such as USDT and tokenized real world assets were unaffected.
Bitcoin’s core network was not affected by the case, and wallets such as Aqua experienced shut downs on Liquid related services. In contrast, approximately 598.5 BTC is still under the hackers control, with no authorization clarifying whether the outstanding funds will be restored.
Liquid may continue its operations once it is verified that L-BTC is totally restored on a 1:1 basis, operates the patched Elements software within the network, and identify reopening the bridge is secure. Such time, the network is still in the process of one of its most major technical barriers.




