The attacker who withdrew roughly 4,000 BTC from Liquid Network's federation wallet over the weekend has returned around 85% of the funds after Blockstream said its bridge nodes had been patched.

The purported white-hat hacker communicated with Blockstream through Bitcoin OP_RETURN messages and PGP-encrypted text. In a message at block 965,875, the party told Blockstream to "fix the bug first" and ensure every node is patched before they would transfer the funds back.

Adam Back-led Blockstream subsequently sent a PGP-signed onchain message saying, "Bridge nodes are patched, safe to return the funds." The signature verifies against the security key published on Blockstream's website. The attacker then returned 3,400 BTC to the federation address in block 965,950, leaving about 598.5 BTC ($47.3 million) in the attacker's wallet.

The exchange followed an earlier message from the attacker offering to send most of the bitcoin back to the federation address. Blockstream had first contacted the party through a transaction at block 965,822, asking it to contact the company’s security team.

Communication between the parties began after Liquid said on Sept. 6 that roughly 4,000 BTC, then worth about $320 million, had been withdrawn from its federation wallet. The funds were withdrawn through the SideSwap Peg-out Authorization Key, but that key itself was not compromised, according to the network.