Self-Proclaimed White-Hat Hackers Drain 4,000 Bitcoin from Liquid Network

On Sunday, the Liquid Network revealed that individuals claiming to be white-hat hackers removed approximately 4,000 bitcoin—valued at around $320 million—from the federation wallet securing L-BTC. The official social media account on X confirmed that bridge nodes were turned off and the sidechain temporarily halted, though other issued assets like USDT, DePix, and real-world assets (RWAs) remained untouched.

Created by Adam Back’s Blockstream, the Liquid Network operates as a federated Bitcoin sidechain. It issues various assets, including L-BTC, which is backed by actual BTC on the primary Bitcoin chain and stored within a large multi-signature arrangement involving 15 corporate and verified members. Moving funds from this treasury requires valid signatures from 11 of the 15 participants. Prior to the security breach, the treasury held more than 4,200 BTC, whereas Blockstream’s proof-of-reserves page now shows just over 207 BTC remaining.

The attackers extracted 4,019.4 BTC from the reserve address through a peg-out transaction utilizing the SideSwap Peg-out Authorization Key. SideSwap functions as a bridge exchange and belongs to the Liquid Federation. Although specific details regarding how the exploit unfolded are still unconfirmed, hackers appear to have exploited an inflation bug on the L-BTC sidechain to mint over 4,000 nonexistent L-BTC tokens, which they then exchanged for on-chain bitcoin from the federation. Because the consensus bug made the transaction look legitimate, the HSM security servers belonging to the federation members signed off on the BTC withdrawal, which was valued at roughly $320 million at the time.

The perpetrator transferred the assets to an address ending in 6gyqjlte and promptly signed a new transaction that included an OP_RETURN arbitrary data field reading, “we are whitehats. contact us on chain.” At the time of writing, those coins remained at that address.

A subsequent small mainnet transaction directed at the hacker’s address included an OP_RETURN message stating, “Please contact security@blockstream.com.” This was presumed to originate from a public Blockstream address, though verification is pending. A later OP_RETURN spend originating from the hacker’s address included the message, “Please contact us on Signal @m671aw.70,” though this might be spam and is not linked to the address holding the stolen capital.

As a countermeasure to the security breach, exchanges were instructed to halt L-BTC deposits and withdrawals. Bridge nodes across the Liquid Network were also disabled to restrict access to the sidechain, which continues to generate blocks.

Samson Mow, CEO of JAN3, stated that Aqua’s Liquid features experienced disruptions while on-chain bitcoin operations continued normally. Other industry wallets utilizing the Liquid Network are anticipated to face impacts as well. Individuals holding L-BTC currently find their savings jeopardized since the underlying BTC cannot be redeemed at the moment. Due to the private architecture of the Liquid chain, public user analytics remain limited, and exact figures regarding how much L-BTC is owned by retail participants versus corporations or Blockstream itself are not widely known. Even so, failure to recover the funds would deal a severe blow to the user base of the Liquid Network.

L-BTC users have few alternatives other than awaiting the outcome of negotiations with the hackers. Given the massive scale of the exploit, evading detection with the entirety of the stolen bitcoin would be exceedingly difficult, though not entirely out of the question. A potential resolution could involve the hackers requesting a finder’s bounty in exchange for returning the bulk of the assets.

What happened to the Liquid Network?

Purported white-hat hackers withdrew about 4,000 bitcoin from the federation wallet backing L-BTC, prompting bridge nodes to be disabled and the sidechain to be paused.

How much were the withdrawn funds worth?

The withdrawn 4,019.4 BTC was worth approximately $320 million at the time of the incident.

Were other assets on the network affected?

No, other issued assets like USDT, DePix, and RWAs remained unaffected by the exploit.

How did the hackers pull off the withdrawal?

They appear to have exploited an inflation bug on the L-BTC sidechain to create unauthorized tokens, executing a peg-out transaction using the SideSwap Peg-out Authorization Key.

spot_imgspot_img

Latest News

New Bitcoin Privacy Tech Threatens Zcash Dominance

Bitcoin Magazine Bitcoin Privacy Breakthrough a Zcash Killer? | Misha Komorov, Alloc Innit Misha Komarov explains Shielded Bitcoin—a proposed ZK privacy protocol using Bitcoin PIPEs to hide transactions with no soft fork needed. This post Bitcoin Privacy Breakthrough a Zcash Killer? | Misha Komorov, Alloc Innit first appeared on Bitcoin Magazine and is written by…

Bitget Users Pull 4,000+ Bitcoins in Hour After $388M Hack

Bitget users withdrew over 4,000 bitcoins worth more than $334 million within one hour after the exchange reopened withdrawals following a $388 million hack attributed to North Korean cyberattack groups.

Bitwise Research Chief: Sovereign Wealth Turning From Gold to Bitcoin

Bitwise research chief Ryan Rasmussen reveals that major institutions like sovereign wealth funds and pensions did not liquidate their Bitcoin holdings during a recent price drop, choosing instead to accumulate more as a hedge against currency debasement.

Tracy Shuchart Discusses Bitcoin and the Commodities Supercycle

NinjaTrader Live senior economist Tracy Shuchart discusses oil market tightening, the Strait of Hormuz supply disruption, refining shortages, hard assets like gold and Bitcoin, and emerging copper and AI infrastructure challenges.

Dan Tapiero States Bitcoin Has Entered a Bull Market

50T Funds CEO Dan Tapiero states Bitcoin and core cryptocurrency assets have entered a new bull market, driven by revenue expansion in stablecoins, tokenization, and leading platforms.
spot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here