After being attacked, Liquid Network, the attacker has returned most of the bitcoins, but there are still approximately 598.5 BTC remaining in the outgoing address unchanged. On September 11th, Blockstream stated that they would not pay a ransom for this portion of funds and claimed that transferring the assets without authorization and demanding compensation in exchange for their return constituted theft rather than "white hat disclosure."
Approximately 4,000 BTC were once transferred out.
This incident occurred last Sunday. Approximately 4,000 BTC were transferred out from the reserves related to the Liquid sidechain, valued at around $320 million according to the text. By Monday of this week, the attackers returned 3,400 BTC, which is about 85% of the total amount that was transferred out. Currently, there are still 598.5 BTC remaining at the initial extraction address.
Blockstream was previously involved in communications, hoping to promote the restoration of network operations. However, the company's latest statement indicates that this should not be construed as an acceptance of the other party's actions, nor does it mean accepting the conditions they proposed.
The vulnerability involves the L-BTC casting and exchange process.
According to the event description, the issue lies in the cache handling of the verification results for the node pair Liquid to range to proof. This flaw allowed attackers to create L-BTC without sufficient support, and then to exchange it for Bitcoin in reserves through SideSwap. SideSwap is one of the federal members and holds the authorization key peg-out.
After the incident, the Liquid reserve once dropped to 197 BTC. Blockstream indicates that the bridging nodes were repaired within 10 hours, and the Elements v23.3.4 version was released on Wednesday. By Thursday, Liquid had resumed block generation and transaction processing, but as a precaution, peg-out remained closed, waiting for the final recovery phase to be completed.
At the same time, Blockstream also reminds that scammers have taken this opportunity to release fake updated websites targeting node operators, attempting to induce people to download fake patches.
The attacker once demanded 10% as a “reward”.
In the postscript of a Bitcoin transaction on Wednesday, the attacker publicly accused Blockstream of insufficient investment in security, stating that they only allocated about $1.5 million, or possibly even less, to protect assets worth approximately $5 billion. The attacker demanded payment of 10% of the amount stolen, referring to it as a “vulnerability bounty”; otherwise, they would leave it to the holders to bear about 15% of the losses.
Blockstream Rejects this request. The company stated that it will not accept the precedent of 'open-source software developers being forced to pay high ransoms for serving the Bitcoin community', nor will it make users bear the losses to fill the gap. The company indicated that if the remaining funds are not returned, it will cooperate with law enforcement agencies, exchanges, and on-chain evidence collection organizations to continue tracking related transactions and evidence.











