The "White hat" party that withdrew nearly 4,000 bitcoin from the Liquid Network federation wallet on Sunday returned 3,400 BTC to the wallet on Monday. About 598 BTC, or 15% of the consolidated pile, stayed at the same holder address as an implied bounty fee worth 48 million dollars. This unprecedented on-chain negotiation unfolded over a tense 24-hour period, highlighting both the vulnerabilities and the emergent communication protocols within the cryptocurrency ecosystem.

Genesis of the Incident: A Vulnerability Exploited

The dramatic events began on Sunday when an entity self-identified as a "White hat" group executed a withdrawal of approximately 4,000 Bitcoin (BTC) from the Liquid Network’s federation wallet. The Liquid Network, a sidechain built by Blockstream, is designed to facilitate faster and more private Bitcoin transactions, with its security relying on a federation of trusted entities. The specific mechanism for this withdrawal was reportedly through the SideSwap peg-out path, a process that converts Liquid Network’s L-BTC back to Bitcoin on the main chain.

Initial reports from Liquid indicated that the Bitcoin peg-out mechanism itself was not compromised, but rather that an underlying bug within the Elements protocol, the technology powering Liquid, was exploited. This bug allowed the unauthorized withdrawal. Crucially, other assets issued on the Liquid Network remained unaffected, and the sidechain was subsequently paused to prevent further exploitation as the situation was assessed. Blockstream, the primary developer of the Liquid Network and Elements, confirmed the incident and the subsequent pause of the sidechain.

The On-Chain Dialogue: A Cryptographic Conversation

What followed was an extraordinary display of communication conducted directly on the Bitcoin blockchain, a testament to the network’s censorship-resistant and immutable nature. The "White hat" group initiated the dialogue by embedding a message within an on-chain transaction: "contact us on chain." This message originated from the address that had received the 4,000 BTC.

A Blockstream-linked address responded with an email address, signaling a willingness to engage. Subsequent messages from this Blockstream address included Electrum-encrypted payloads and PGP signatures, verifiable against Blockstream’s publicly available security key. This ensured the authenticity of communications and provided a secure channel for sensitive information exchange.

The "White hats" then used another transaction to convey a crucial question: "whether sending most back to the federation script was acceptable." This transaction, while carrying the message in its data field, also included a nominal Bitcoin output as a carrier. The implication was clear: they were prepared to return a significant portion of the funds, contingent on an agreement.

The urgency of the situation was underscored by a subsequent message from the "White hats": "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." This message, accompanied by an encrypted blurb of text sent to Blockstream’s PGP key, indicated that the group had identified a critical vulnerability and prioritized its remediation before completing the fund return. This altruistic approach, if genuine, suggests a motive beyond mere financial gain, aiming to secure the network for all users.

Blockstream responded promptly, confirming the fix. In a clear-signed reply, they stated, "Yes, thank you." Hours later, another clear-text message from Blockstream provided further assurance: "Bridge nodes are patched, safe to return the funds." This communication confirmed that the critical vulnerability had been addressed and that the Liquid Network was prepared to receive the returned funds.

The Resolution: A Partial Return and a Significant Bounty

Following Blockstream’s confirmation, the "White hat" group executed a transaction at 16:09 UTC on September 7th. This transaction, identified by the hash a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d, returned precisely 3,400 BTC to the designated Liquid peg script address. The remaining 598.5 BTC was sent back to the "White hat" hacker address as transaction change.

This return represented 85% of the initially withdrawn funds. The remaining 15%, totaling approximately 598 BTC, was retained by the "White hat" group. At the time of the transaction, this retained amount was valued at roughly $48 million USD, a substantial sum that has generated considerable discussion within the cryptocurrency community.

Community Reaction and Blockstream’s Response

The outcome of this incident has elicited mixed reactions. Some observers on social media platforms, such as X (formerly Twitter), have lauded the "White hat" group’s decision to return the majority of the funds, viewing it as a more ethical outcome than keeping the entire amount. The act of identifying and reporting a critical bug, while retaining a significant portion as a reward, is seen by some as a novel and effective bug bounty mechanism, albeit one initiated through a rather unconventional method.

However, others have expressed shock at the size of the bounty. While 15% may be a common percentage for bug bounties in traditional software development, the sheer magnitude of the sum involved in this case, nearing $50 million, has raised eyebrows. It is understood that Blockstream was not entirely pleased with the size of the fee.

Following the successful return of the majority of the funds, a series of encrypted messages were exchanged between Blockstream and the "White hat" group. These exchanges, occurring hours after the main issue was resolved, are speculated to have involved discussions regarding the bounty amount, possibly after internal discussions at Blockstream and legal consultations. One final encrypted message was posted from Blockstream an hour later.

The "White hats" responded with two encrypted messages, followed by another from Blockstream. The exchange concluded with the "White hat" group publishing a simple, yet poignant, "sad face emoji" (😔) on-chain. This emoji is widely interpreted as an indication that negotiations to reduce the bounty fee were unsuccessful, and that the "White hat" group stood firm on their retained amount. The cryptic nature of these encrypted exchanges means the specifics of the negotiations remain unknown, and Blockstream has yet to issue a formal statement beyond its initial advisories.

Analysis and Implications: The Future of "White Hat" Interventions

This incident raises several important points for the cryptocurrency industry. Firstly, it highlights the persistent challenge of securing complex blockchain protocols. Despite extensive development and security audits, critical vulnerabilities can still emerge. The Elements protocol, and by extension the Liquid Network, faced a significant test, and the ability to patch the issue swiftly was paramount.

Secondly, the on-chain communication protocol employed by the "White hat" group and Blockstream demonstrates the resilience and utility of Bitcoin’s immutable ledger as a communication channel, especially in situations where traditional communication channels might be compromised or unreliable. The use of PGP signatures and encrypted payloads ensured the integrity and confidentiality of the dialogue.

Thirdly, the incident brings to the forefront the ongoing debate around bug bounty programs within the cryptocurrency space. While the "White hat" group’s actions could be seen as a high-stakes form of ethical hacking, the significant financial reward they secured raises questions about incentives, transparency, and the potential for future "white hat" interventions to become more aggressive if perceived vulnerabilities are not addressed promptly. The precedent set by this 15% bounty, valued at tens of millions of dollars, could influence how future security researchers approach similar situations.

The fact that Liquid and Blockstream have not issued a new official statement since their initial advisories, beyond the on-chain communications, suggests they are likely managing the aftermath internally. The pause on the Liquid Network sidechain was a necessary step to contain the immediate threat. The successful return of the funds, however, allows for the network’s eventual restoration.

Researchers and enthusiasts are actively tracking the ongoing narrative. A dedicated website compiles the full chat, offering a "vibe-coded" visualization of the exchanges. Additionally, resources like Sjors’s GitHub gist and Alex Thorn’s analysis from Galaxy Research provide further on-chain data and commentary, allowing the community to scrutinize the events and their potential ramifications.

The saga of the Liquid Network’s stolen Bitcoin and its subsequent on-chain recovery is far from over. While the immediate threat has been neutralized and the majority of funds returned, the implications of this event—from the nature of bug bounties to the trust dynamics within federated sidechains—will likely be debated and analyzed within the blockchain community for some time to come. The "White hat" group’s actions, while controversial in their execution and reward, have undeniably brought a critical security flaw to light and demonstrated a unique, albeit high-risk, method of resolution.

Leave a Reply

Your email address will not be published. Required fields are marked *