The recent Liquid Network exploit has taken an interesting turn.
Around 4,000 BTC was withdrawn from Liquid’s federation reserves. After the vulnerability was patched, around 3,400 BTC was returned, while approximately 598.5 BTC remained with the attackers.
What I find interesting is that the recovery can be independently checked on the Bitcoin blockchain.
The 3,400 BTC return was included in Bitcoin block 965,950.
Blockchain evidence:
Transaction:
https://mempool.space/tx/a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46dBitcoin block 965,950:
Block:
[url=https://blockchair.com/bitcoin/block/965950]https://blockchair.com/bitcoin/block/965950It’s a pretty good example of how Bitcoin transactions remain publicly verifiable even when the people behind them aren’t known.
What do you think - did the attackers return the BTC because they realized it would be difficult to move without being traced?