Liquid Network has been sitting on frozen peg-outs for 35 days after nearly 4,000 BTC got drained. The 'white hat' hacker gave back most of the loot, then quietly kept the rest as a 'bounty'. LBTC holders still can't turn their tokens into real bitcoin. Some bounty program.
▪️ The attacker exploited a vulnerability in Liquid's Elements software and pulled nearly 4,000 BTC out of the L2 network. Nice hole to find.
▪️ By Sept. 7 they had returned about 3,400 BTC, then kept 598.5 BTC and demanded a 10% bounty from Blockstream. Negotiating with a straight face, that takes talent.
▪️ Blockstream refused outright and demanded the rest back. Nothing came back. The 598.5 BTC is still sitting in that wallet, and it's not going anywhere on its own.
▪️ Peg-out operations remain suspended. Liquid's Sept. 29 update said an independent external audit of Elements v23.3.4 is underway. Translation: they're still checking how the door got opened.
▪️ The Liquid Federation is replacing PAK list entries and moving all peg-out keys to cold storage before restarting redemptions. Keys go to cold storage after the fire, very on brand.
▪️ Holders who couldn't wait moved coins out through SideSwap and SideShift.ai, paying roughly 5% in spread and fees, with weeks lost to thin liquidity. Those who waited still get to hold the bag.
📊 Drained from Liquid:
~4,000 BTC📊 Returned by attacker:
3,400 BTC📊 Still held by attacker:
598.5 BTC ($49.69M)📊 Liquid backing:
86%Every LBTC holder is down 14% on backing, and nobody has a restart date. The attacker's wallet is still getting address-poisoning spam and weird OP_RETURN messages, which is exactly what a dead end looks like. If you hold LBTC, the real question is whether the audit and key rotation finish before the people who paid the 5% exit tax are the only ones who got out.
💬 «Communications have been sparse and inconsistent.» — Sovereign Money
🔮 A 'white hat' sitting on 598 BTC and asking for 10% is not a bounty. It's a ransom with a nicer name.
@tontiger_fam