Key Takeaways

  • Nearly 4,000 BTC was drained from Liquid’s federation wallet, removing about 95% of its bitcoin reserves.

  • The attackers returned 3,400 BTC after demanding that Blockstream patch the software bug behind the exploit.

  • Liquid remains under pressure to secure its nodes, explain the breach and address the remaining 600 BTC shortfall.

Liquid Network Faces Major Security Breach

Liquid Network has paused activity after nearly 4,000 bitcoin worth about $320 million was taken from its federation wallet.

The people behind the withdrawal claim they are “white-hat hackers” and said they will return most of the bitcoin after Blockstream fixes the software bug that allowed the funds to be taken.

Liquid Network published an announcement, saying that it is aware of the incident, and they are communicating with the hackers to resolve the issue.

The attackers partially followed through on their promise, returning 3,400 BTC of the 4,000 BTC they took. However, 600 BTC still remain under the hackers’ control. The hackers have not revealed who they are.

The incident happened on September 6. Liquid said about 4,000 BTC was withdrawn from its federation wallet, which held roughly 4,200 BTC before the incident.

That means around 95% of the wallet's bitcoin was removed.

On-chain data showed that about 3,998.5 BTC was moved to another bitcoin address.
Liquid said the withdrawal went through a Peg-out Authorization Key, or PAK, connected to SideSwap. However, Liquid said the PAK itself was not compromised and that there was no evidence that other federation keys had been compromised.

The transaction that drained the Liquid Federation’s wallets — Mempool.space

The exact software bug that made the withdrawal possible has not yet been publicly disclosed.

After discovering the incident, Liquid disabled its bridge nodes and asked exchanges to stop L-BTC deposits and withdrawals. The network was effectively put on hold while the federation investigated.

Other assets on Liquid, including USDT and DePix, were not directly stolen.

After taking the Bitcoin, the attackers sent a message through the Bitcoin blockchain saying, “we are whitehats. contact us on chain.”

A white-hat hacker is normally someone who finds a security flaw and uses it to help a project fix the problem rather than steal funds. That is why that description is being questioned in this case.

Analysts argue legitimate white-hat hackers would not normally take hundreds of millions of dollars first and negotiate afterward. The incident was compared with other major exploits with digital asset exchanges where attackers later tried to negotiate with the victims.

Still, there is one unusual aspect of the Liquid incident: the attackers opened a line of communication with Blockstream and said they intended to return most of the bitcoin; a promise they have partially fulfilled.

The two sides have been communicating through bitcoin transactions containing messages.

According to Galaxy Research head Alex Thorn, Blockstream first contacted the attackers by sending 1,000 satoshis with a message directing them to its security team.

A later transaction included encrypted information and a PGP signature that could be verified against Blockstream's published key.

Blockstream’s encrypted message — Mempool.space

The attackers responded by sending their own bitcoin transaction and asking whether returning “most” of the funds to Liquid's federation wallet would be acceptable.

They then gave Blockstream a condition for repayment.

“Please fix the bug first,” the attackers said. “Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

The hackers message in a Bitcoin transaction — mempool.space

It is not yet known why the attackers chose to use a public communication channel rather than a private one, such as email. One possibility is that they wanted the exchange to be visible to the public.

The attackers have returned 3,400 BTC, but have not said exactly what they plan to do with the remaining 600.

The attackers returned 3,400 BTC — Mempool.space

The biggest question for Liquid users is what happens to L-BTC.

Liquid allows users to lock bitcoin on the Bitcoin network and receive an equivalent amount of L-BTC on the Liquid sidechain. The bitcoin held by Liquid’s federation provides the backing for these tokens, which are designed to maintain a 1:1 peg with on-chain bitcoin.

Once issued on the sidechain, L-BTC can be transferred and traded in an environment that offers faster and more confidential transactions than Bitcoin’s main chain. In this sense, Liquid is designed to address two commonly cited limitations of Bitcoin: transaction speed and privacy.

Now that the hackers have returned most of the money, Liquid and its federation will have to deal with the remaining shortfall.

Blockstream's immediate task is to identify the bug, patch it and make sure the affected federation nodes are running the fixed software.

Liquid also needs to explain exactly how the withdrawal was possible despite the PAK and other authorization controls.

Until those questions are answered, the network remains under pressure.

100% of the sats go directly to the author

Latest on YouTube


Reply

Avatar

or to participate