Unidentified actors holding nearly 4,000 BTC from the Liquid Network have demanded a network patch before returning the funds.
The actors made the offer through Bitcoin transactions on September 7.
They asked whether Liquid’s federation would accept most of the Bitcoin back.
However, they attached a condition to the offer. They want Blockstream to fix the vulnerability that they say still exposes the network.
The actors also want every federation node to receive the patch. They said they would return the Bitcoin after confirming that Blockstream had fixed the problem.
Galaxy Research head Alex Thorn reconstructed the messages and detailed the exchange in an analysis of the Bitcoin transactions.
Liquid has not confirmed the proposed return. In addition, the actors have not sent any of the Bitcoin back to the federation as of press time.
The actors have also not identified themselves or said exactly how much Bitcoin they would return. They also have not given Liquid a deadline for the transfer.
Hackers Offer to Return Most of the Bitcoin from Liquid Wallet
The incident began on September 6 when roughly 3,996 BTC left Liquid’s federation wallet. Bitcoin miners confirmed the transaction in block 965,783.
Liquid later confirmed that approximately 4,000 BTC had left the wallet. The network described the people behind the withdrawal as purported white-hat hackers.
However, Liquid has not confirmed that the actors had permission to access the funds. Their messages also do not explain why they took the Bitcoin.
Blockstream started communicating with the address holding the Bitcoin at block 965,822. It sent 1,000 satoshis and directed the recipient to its security team.
Another transaction contained encrypted material and a detached signature. The signature matched Blockstream’s published PGP key.
The actors have not explained what they mean by “most” of the Bitcoin.
Therefore, Liquid cannot yet estimate how much of the funds it could recover.
The network can only confirm a recovery after the Bitcoin reaches a federation-controlled address.

Blockstream Still Needs to Fix the Bug
Blockstream now needs to identify the vulnerability and develop a fix.
The blockchain company has not announced a patch version or said when Liquid will restore its bridge operations.
Liquid has not publicly explained the vulnerability behind the withdrawal.
The network has only provided limited details about how the Bitcoin left its wallet.
Liquid said the withdrawal used SideSwap’s Peg-out Authorisation Key, known as the PAK.
However, Liquid said it found no evidence that someone compromised the key.
The actors have not said whether they expect a reward for returning the Bitcoin.
They have also not said whether they will keep any portion of the funds.

