Hackers Return Most of $320 Million Stolen from Liquid Network After Demanding Bug Fix
A coordinated cyberattack on the Liquid Network, the Bitcoin sidechain operated by Blockstream, resulted in the overnight loss of roughly $320 million in digital assets. The breach, initially reported by security outlet Security Affairs, targeted the network's infrastructure that enables dozens of cryptocurrency exchanges to settle trades and move funds more quickly than on the main Bitcoin chain.
According to the initial findings, the attackers exploited a vulnerability that allowed them to siphon tokens from the network's hot wallets. The theft was detected in the early hours, prompting an emergency response from the Liquid team and its partner exchanges. While the precise method of entry has not been disclosed, experts note that sidechains, by design, introduce additional layers of software that can become attack vectors if not rigorously audited.
In an unusual turn, the perpetrators did not demand a traditional ransom in Bitcoin or other cryptocurrencies. Instead, they issued a demand for a “bug fix” that would address the flaw they had used to extract the funds. The request was communicated through the same channels the hackers had used to move the assets, effectively turning the incident into a negotiation over code rather than a simple monetary payout.
After a brief period of back‑and‑forth, the Liquid Network announced that the majority of the stolen funds had been returned. While exact figures were not released, the company indicated that most of the $320 million was recovered, mitigating what could have been a catastrophic loss for the ecosystem of exchanges that rely on the sidechain for rapid settlement.
The episode underscores the growing tension between speed and security in the cryptocurrency space. Sidechains like Liquid promise near‑instant transfers and lower fees, but they also expand the attack surface beyond Bitcoin’s base layer. Industry observers suggest that the incident will likely accelerate calls for more rigorous security audits, formal verification of smart‑contract‑like code, and perhaps a reevaluation of how hot wallets are managed on such platforms.
Blockstream has pledged to conduct a thorough post‑mortem and to release a detailed technical report once the investigation concludes. In the meantime, exchanges connected to Liquid are reviewing their exposure and may temporarily shift to alternative settlement methods while confidence in the network’s security is restored. The rapid return of the funds, however, has been welcomed as a sign that the attackers were motivated more by leverage over the code than by pure profit.
Regulators and law‑enforcement agencies have been alerted, though no arrests have been reported. The incident adds to a growing list of high‑profile cryptocurrency breaches that have highlighted the need for clearer standards and cooperation across the industry. As the market watches how Liquid implements its promised fixes, the broader crypto community is likely to scrutinize sidechain architectures for similar vulnerabilities, aiming to prevent a repeat of this costly episode.
Comments (0)
Be the first to comment.
Join the discussion