#Liquid network suffers a $320 million attack: the hacker returns $268 million the next day, keeping $47 million—was this white-hat justice, or a form of extortion?
📢 Join the group to get the latest announcement interpretations
First, a question: if one person steals $320 million, then returns $268 million the next day, and keeps $47 million—should we call him a hacker, or a Robin Hood?
This dramatic saga unfolded on the Bitcoin sidechain Liquid Network. On Sunday, someone withdrew nearly 4,000 BTC in one go from its reserve wallet—worth about $320 million at the time. The reserves were reportedly drained by as much as 90%. On-chain data immediately exploded, and the market’s first reaction was almost reflexive: the hacker is going to dump.
But the next part of the story doesn’t follow the usual script.
The attacker left messages on-chain, claiming to be a “white hat.” He said there was a vulnerability in the underlying code of Liquid and SideSwap, demanding that the official side patch the issue first, before discussing any return of funds. This kind of “technical hostage-taking” puts the incident in a gray zone—call it theft, and they don’t ask for money, only for a bug fix; call it good faith, and $320 million in real value truly has been pulled from someone else’s wallet.
The latest development: in the early hours today, this “white hat” transferred 3,400 BTC (about $268 million) back to the Liquid wallet—returning 85% within a day. The remaining 598.5 BTC, worth roughly $47.2 million, continues to be kept by them.
What’s most worth scrutinizing isn’t the money—it’s the vulnerability itself. Liquid has long touted that it uses a federated multi-signature mechanism, which is safer than a single-signature setup. But this breach wasn’t a failure of the multi-sig logic. It was the underlying protocol software—according to the audit report, the multi-sig is guarding the door, yet the vulnerability still remained hidden for who knows how long. This is already the Nth time this year that a system that looked “bulletproof” on paper has had its stronghold taken down.
Now the suspense centers on those 598 BTC: is this industry-standard “bug bounty,” or a veiled ransom? Does the official side acknowledge it? And if they do, does that effectively amount to declaring—so long as the technical capability is strong enough, one can take out $300 million from others and then return 85%, earning $47 million legally?
What do you think—does this count as a white-hat act of righteousness, or extortion and criminal wrongdoing? See the comments.#Zcash周涨45%创2016年来新高
📢 Join the group to get the latest announcement interpretations
First, a question: if one person steals $320 million, then returns $268 million the next day, and keeps $47 million—should we call him a hacker, or a Robin Hood?
This dramatic saga unfolded on the Bitcoin sidechain Liquid Network. On Sunday, someone withdrew nearly 4,000 BTC in one go from its reserve wallet—worth about $320 million at the time. The reserves were reportedly drained by as much as 90%. On-chain data immediately exploded, and the market’s first reaction was almost reflexive: the hacker is going to dump.
But the next part of the story doesn’t follow the usual script.
The attacker left messages on-chain, claiming to be a “white hat.” He said there was a vulnerability in the underlying code of Liquid and SideSwap, demanding that the official side patch the issue first, before discussing any return of funds. This kind of “technical hostage-taking” puts the incident in a gray zone—call it theft, and they don’t ask for money, only for a bug fix; call it good faith, and $320 million in real value truly has been pulled from someone else’s wallet.
The latest development: in the early hours today, this “white hat” transferred 3,400 BTC (about $268 million) back to the Liquid wallet—returning 85% within a day. The remaining 598.5 BTC, worth roughly $47.2 million, continues to be kept by them.
What’s most worth scrutinizing isn’t the money—it’s the vulnerability itself. Liquid has long touted that it uses a federated multi-signature mechanism, which is safer than a single-signature setup. But this breach wasn’t a failure of the multi-sig logic. It was the underlying protocol software—according to the audit report, the multi-sig is guarding the door, yet the vulnerability still remained hidden for who knows how long. This is already the Nth time this year that a system that looked “bulletproof” on paper has had its stronghold taken down.
Now the suspense centers on those 598 BTC: is this industry-standard “bug bounty,” or a veiled ransom? Does the official side acknowledge it? And if they do, does that effectively amount to declaring—so long as the technical capability is strong enough, one can take out $300 million from others and then return 85%, earning $47 million legally?
What do you think—does this count as a white-hat act of righteousness, or extortion and criminal wrongdoing? See the comments.#Zcash周涨45%创2016年来新高
