Liquid attacker keeps $47 million for themselves — white hat bounty or veiled extortion?
- Key Takeaways: On September 6, 2024, an attacker exploited a vulnerability in Elements, the underlying software of the Liquid Network, to mint approximately 4,000 LBTC out of thin air, then swapped them for approximately 3,998.5 real BTC (worth around $320 million) through SideSwap's normal withdrawal channel. The attacker claimed to be a white hat and returned 3,400 BTC, but withheld approximately 598.5 BTC (around $47 million) as a "reward." Officials have not yet confirmed this as a bug bounty, sparking debate over the boundaries of white hat behavior.
- Key Elements:
- The attack method did not involve private key leakage or theft of authorized keys, but rather exploited an Elements software vulnerability to mint "fake LBTC" without reserve backing, bypassing multi-signature verification through the burn-and-withdraw process to extract real BTC.
- Liquid's multi-signature wallet employs an 11-of-15 mechanism, but the multi-signature only confirms sufficient authorization—it cannot detect whether assets were generated through a vulnerability, exposing a fundamental flaw in the asset verification process.
- The attacker left a message in the OP_RETURN field of Bitcoin transactions: "We are white hats, please contact us on-chain." The two parties negotiated via on-chain messages, with the attacker requiring the fix to be completed before returning the funds.
- On September 7, the attacker returned 3,400 BTC but transferred the remaining 598.5 BTC to an address under their control. With no on-chain agreement or bug bounty arrangement in place, officials continue to pursue recovery and treat it as assets subject to recoupment.
- The core dispute centers on white hat procedures: traditional white hats report vulnerabilities before receiving rewards, whereas this attacker first withdrew nearly 95% of reserves and then unilaterally withheld 15% as potential incentive—which some argue more closely resembles "veiled extortion."
- Blockstream has urgently planned to release Elements v23.3.4 to patch the vulnerability, with Functionary operators adjusting the network to reject invalid peg-outs. Liquid has not yet fully resumed operations.
Original by Odaily Planet Daily (@OdailyChina)
Author: Asher (@Asher_ 0210)

On September 6, an attacker exploited a vulnerability in the Elements software to mint approximately 4,000 LBTC out of thin air, and then used SideSwap's normal withdrawal channel to exchange approximately 3,998.5 BTC from the Liquid multi-sig wallet, valued at around $320 million.
However, the attacker subsequently left a message in a Bitcoin transaction: "We are whitehats, please contact us on-chain." After Blockstream patched the vulnerability, the attacker returned 3,400 BTC but retained the remaining ~598.5 BTC in addresses under their control, valued at approximately $47 million.
Currently, Blockstream is in communication with the attacker, attempting to recover the remaining 598.5 BTC, and the official team has not confirmed this as a bug bounty.

Returning 85% while keeping 15% – is this a costly whitehat operation, or did the attacker set their own hefty compensation package under the guise of returning funds?
Minting LBTC from Thin Air to Drain Nearly 4,000 Real BTC
Liquid Network is a Bitcoin sidechain launched by Blockstream in 2018. Unlike the Lightning Network, which primarily serves daily payments, Liquid focuses more on Bitcoin settlements between exchanges and institutions, while also supporting the issuance of digital assets such as stablecoins and securities. The number of institutions participating in Liquid's governance and operations has grown from the initial 23 to 87, and the total value of RWA assets issued on Liquid now exceeds $5 billion.
On September 6, Liquid suffered its most severe security incident since launch, with the related withdrawals executed in two transactions. The attacker first withdrew ~2.5 BTC as a test, then transferred approximately 3,996 BTC. These two transactions accounted for roughly 95% of the multi-sig wallet's Bitcoin reserves before the incident, leaving just ~197 BTC in the wallet after the funds were moved. Liquid subsequently shut down its bridge nodes, halting network operations, and multiple exchanges suspended LBTC deposits and withdrawals.
This incident was not caused by a leak of the multi-sig wallet's private keys, nor was SideSwap's Peg-out Authorization Key, used to authorize withdrawals, compromised. The real issue lay in the Elements software underlying Liquid.
According to information disclosed by SideSwap, the attacker exploited a vulnerability in the Elements software to mint approximately 4,000 LBTC with no real BTC backing, then sent them to SideSwap's Peg-out service. From the system's perspective, these vulnerability-minted LBTC were indistinguishable from legitimate assets. SideSwap therefore burned the LBTC and submitted the withdrawal request through its normal process, prompting the Liquid multi-sig wallet to pay out the corresponding real BTC to the attacker's address.
In simple terms, the attacker did not directly breach the wallet holding the BTC, but instead fabricated "fake LBTC" that could deceive the system, and then swapped them for real BTC through the normal withdrawal channel.
The Liquid multi-sig wallet employs an 11-of-15 mechanism, requiring approval from at least 11 of the 15 multi-sig members for any withdrawal. However, this incident demonstrates that multi-sig only confirms that a withdrawal has received sufficient authorization – it cannot determine whether the LBTC entering the withdrawal process was generated through a vulnerability. When asset verification fails, even more signatures can ultimately greenlight an erroneous transaction.
A Negotiation Unfolding on the Bitcoin Blockchain
After moving the funds, the attacker left a message in the OP_RETURN field of a Bitcoin transaction: "we are whitehats. contact us on chain."
Blockstream sent 1,000 sats to the attacker's address, requesting them to contact the security team. The two parties subsequently engaged in on-chain communication via OP_RETURN, PGP signatures, and encrypted messages. The attacker stated a willingness to return the "majority of funds" after the vulnerability was patched, and demanded that Blockstream ensure all bridge nodes were updated. Once the fix was complete, Blockstream informed the attacker via a signed message: "Bridge nodes have been patched, funds can be safely returned."
On September 7, the attacker transferred 3,400 BTC back to the Liquid multi-sig wallet while moving the remaining ~598.5 BTC to an address under their control. However, in the publicly disclosed on-chain communications between the two parties, there was neither an agreement on how much BTC the attacker could retain, nor any negotiation designating the 598.5 BTC as a bug bounty.
According to Liquid's latest security incident report, Blockstream is still in communication with the attacker, attempting to recover the remaining 598.5 BTC. This suggests that Blockstream's earlier agreement for the attacker to return the "majority of funds" does not imply recognition of the attacker's right to keep BTC valued at approximately $47 million. At least in the official narrative, these funds remain assets pending recovery – not a confirmed whitehat bounty.
$47 Million: Bounty or Extortion?
Supporters of the attacker argue that if a malicious hacker had discovered the vulnerability first, Liquid could have lost its entire Bitcoin reserve. In this case, the attacker required Blockstream to complete the patch first and ultimately returned 85% of the funds. Even if the nearly 600 BTC are never returned, Liquid still avoided a far worse outcome compared to losing all of its funds.
Cøbra, the anonymous owner of Bitcoin.org, believes whitehats deserve rewards commensurate with the losses they help prevent. Yu Xian, founder of SlowMist, has also suggested that high-value theft incidents could gradually establish a "15% minimum" return bounty consensus. In their view, higher bounties incentivize vulnerability discoverers to return funds rather than simply absconding with everything.

The root of the controversy lies in the "procedure" – traditional whitehat disclosure typically involves reporting the vulnerability first, followed by the project team paying a reward according to established rules or negotiated terms. The Liquid attacker, however, first withdrew nearly the entire reserve, then unilaterally kept 15%. Ledger CTO Charles Guillemet has therefore questioned whether this approach more closely resembles demanding payment in exchange for returning funds, rather than legitimate whitehat behavior.
For Liquid, recovering 3,400 BTC merely provides temporary relief from the reserve crisis. The vulnerability fix has now entered internal and external review phases, with the official plan to urgently release Elements v23.3.4, followed by network adjustments completed by Functionary operators to reject previously invalid Peg-outs and restore network operations.
Whether the remaining funds can be recovered and when Liquid will fully resume operations still depends on future developments. But the latest official statements have made this controversy much clearer: an attacker can call themselves a whitehat, yet they cannot unilaterally define the $47 million they withheld as a bug bounty.


