Self-Proclaimed White-Hat Hackers Drain 4,000 Bitcoin from Liquid Network

On Sunday, the Liquid Network revealed that individuals claiming to be white-hat hackers removed approximately 4,000 bitcoin—valued at around $320 million—from the federation wallet securing L-BTC. The official social media account on X confirmed that bridge nodes were turned off and the sidechain temporarily halted, though other issued assets like USDT, DePix, and real-world assets (RWAs) remained untouched.

Created by Adam Back’s Blockstream, the Liquid Network operates as a federated Bitcoin sidechain. It issues various assets, including L-BTC, which is backed by actual BTC on the primary Bitcoin chain and stored within a large multi-signature arrangement involving 15 corporate and verified members. Moving funds from this treasury requires valid signatures from 11 of the 15 participants. Prior to the security breach, the treasury held more than 4,200 BTC, whereas Blockstream’s proof-of-reserves page now shows just over 207 BTC remaining.

The attackers extracted 4,019.4 BTC from the reserve address through a peg-out transaction utilizing the SideSwap Peg-out Authorization Key. SideSwap functions as a bridge exchange and belongs to the Liquid Federation. Although specific details regarding how the exploit unfolded are still unconfirmed, hackers appear to have exploited an inflation bug on the L-BTC sidechain to mint over 4,000 nonexistent L-BTC tokens, which they then exchanged for on-chain bitcoin from the federation. Because the consensus bug made the transaction look legitimate, the HSM security servers belonging to the federation members signed off on the BTC withdrawal, which was valued at roughly $320 million at the time.

The perpetrator transferred the assets to an address ending in 6gyqjlte and promptly signed a new transaction that included an OP_RETURN arbitrary data field reading, “we are whitehats. contact us on chain.” At the time of writing, those coins remained at that address.

A subsequent small mainnet transaction directed at the hacker’s address included an OP_RETURN message stating, “Please contact security@blockstream.com.” This was presumed to originate from a public Blockstream address, though verification is pending. A later OP_RETURN spend originating from the hacker’s address included the message, “Please contact us on Signal @m671aw.70,” though this might be spam and is not linked to the address holding the stolen capital.

As a countermeasure to the security breach, exchanges were instructed to halt L-BTC deposits and withdrawals. Bridge nodes across the Liquid Network were also disabled to restrict access to the sidechain, which continues to generate blocks.

Samson Mow, CEO of JAN3, stated that Aqua’s Liquid features experienced disruptions while on-chain bitcoin operations continued normally. Other industry wallets utilizing the Liquid Network are anticipated to face impacts as well. Individuals holding L-BTC currently find their savings jeopardized since the underlying BTC cannot be redeemed at the moment. Due to the private architecture of the Liquid chain, public user analytics remain limited, and exact figures regarding how much L-BTC is owned by retail participants versus corporations or Blockstream itself are not widely known. Even so, failure to recover the funds would deal a severe blow to the user base of the Liquid Network.

L-BTC users have few alternatives other than awaiting the outcome of negotiations with the hackers. Given the massive scale of the exploit, evading detection with the entirety of the stolen bitcoin would be exceedingly difficult, though not entirely out of the question. A potential resolution could involve the hackers requesting a finder’s bounty in exchange for returning the bulk of the assets.

What happened to the Liquid Network?

Purported white-hat hackers withdrew about 4,000 bitcoin from the federation wallet backing L-BTC, prompting bridge nodes to be disabled and the sidechain to be paused.

How much were the withdrawn funds worth?

The withdrawn 4,019.4 BTC was worth approximately $320 million at the time of the incident.

Were other assets on the network affected?

No, other issued assets like USDT, DePix, and RWAs remained unaffected by the exploit.

How did the hackers pull off the withdrawal?

They appear to have exploited an inflation bug on the L-BTC sidechain to create unauthorized tokens, executing a peg-out transaction using the SideSwap Peg-out Authorization Key.

spot_imgspot_img

Latest News

Hargreaves Lansdown changes direction to offer bitcoin trading

British investment firm Hargreaves Lansdown has reversed its previous stance to roll out bitcoin and crypto exchange-traded notes for retail investors, despite earlier warnings labeling the cryptocurrency as high-risk and volatile.

Trezor Security Breach Exposes 67,000 More US Users

Hardware wallet maker Trezor revealed that a data breach involving third-party vendor ShipMonk is significantly larger than first estimated, exposing personal details for an additional 67,000 U.S. customers.

IMF Clarifies El Salvador Did Not Use Public Funds for Bitcoin

According to the IMF, El Salvador has not used public funds for its bitcoin reserves since its last loan review, acquiring the cryptocurrency entirely through private donations instead.

Bitcoin Falls Under $80,000 Following Robust US Jobs Data

Bitcoin fell below $80,000 following an unexpectedly strong U.S. jobs report, which heightened concerns about potential Federal Reserve interest rate hikes and impacted the cryptocurrency market.

National Sheriffs’ Association Withdraws Opposition to Clarity Act

The National Sheriffs’ Association has withdrawn its opposition to the crypto Clarity Act, adopting a neutral stance as a Senate vote approaches this month to establish a digital asset regulatory framework.
spot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here