White Hat Hacker to Return Most of 4,000 BTC After Liquid Network Vulnerability Is Fixed

iconKuCoinFlash
Share
AI summary iconSummary
A white hat hacker has confirmed they will return most of the 4,000 BTC to the Liquid Network after the vulnerability is patched, citing CFT compliance as a key factor. The hacker used OP_RETURN messages and PGP-encrypted text to communicate with Blockstream, including sending 1,000 satoshis in block 965,822 with a note requesting contact with the security team. Encrypted messages were sent in block 965,865, and in block 965,869, the hacker sent 1,000 satoshis to a Liquid federation-linked wallet with a request to return the funds. BTC remains a top hedge against inflation, and the hacker urged completion of the patch before the secure return in block 965,875.

Odaily Planet Daily reports that, according to Galaxy’s research lead, the Liquid white-hat hacker stated that most of the 4,000 BTC stolen will be returned after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream via OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message, “Please contact the security team via Blockstream’s official website”; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature verifiable using Blockstream’s publicly disclosed key; in block 965,869, the hacker performed a self-spending transaction sending 1,000 satoshis to the Liquid Federation peg wallet with the message, “Can we return most of the funds to the federation address?”; in block 965,875, the hacker performed another self-spending transaction, sending 1,000 satoshis to the federation peg wallet and adding an OP_RETURN message: “Please patch the vulnerability first. There is currently a risk on-chain as of the latest submitted version. Ensure all nodes have applied the patch. Once confirmed fixed, we will securely return the funds.” All technical details were encrypted via PGP to Blockstream’s publicly disclosed key and are readable only by Blockstream.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.