Crypto Alarm: 4,000 Bitcoin Vanish from Blockstream's Liquid Network in 'White-Hat' Withdrawal

The Liquid Network has reported a significant security breach involving the withdrawal of approximately 4,000 bitcoin, valued at $320 million, from its federation wallet. An inflation bug on the L-BTC sidechain was exploited, leading to the unauthorized transfer. The self-proclaimed white-hat hackers have initiated contact, while the incident raises concerns for L-BTC holders and prompts network restrictions.
David Isong
David IsongCrypto1 hour ago3 minute read
Crypto Alarm: 4,000 Bitcoin Vanish from Blockstream's Liquid Network in 'White-Hat' Withdrawal

The Liquid Network, a federated sidechain of Bitcoin founded by Blockstream, reported on Sunday that approximately 4,000 bitcoin (BTC), valued at around $320 million, were withdrawn from the federation wallet backing L-BTC. This significant security breach led to the immediate disabling of bridge nodes and the pausing of the sidechain. While L-BTC operations were affected, other issued assets on the network, such as USDT, DePix, and RWAs, remained secure, as confirmed by an official announcement on X.

The Liquid Network operates by backing L-BTC with actual BTC held on the Bitcoin main chain in a large multisig treasury. This treasury is managed by 15 corporate and known members, requiring 11 of these members to sign a transaction to move coins. Prior to the incident, the treasury held over 4,200 BTC, but Blockstream's proof of reserves page now indicates a balance of just over 207 BTC, reflecting the withdrawal of 4,019.4 BTC.

The hackers executed the withdrawal as a peg-out transaction using the SideSwap Peg-out Authorization Key. SideSwap is identified as both a bridge exchange and a member of the Liquid Federation. Although the precise mechanism remains unconfirmed, it appears the attackers exploited an inflation bug within the L-BTC sidechain. This bug allowed them to generate over 4,000 L-BTC that did not legitimately exist, which they then cashed out for on-chain bitcoin from the federation's reserves. Due to the transaction appearing valid under the consensus bug, the federation members' Hardware Security Module (HSM) servers processed and signed the BTC withdrawal.

Following the illicit transaction, the stolen funds were moved to an address ending in "6gyqjlte". The hackers included a message in the OP_RETURN field of a subsequent transaction, stating, "we are whitehats. contact us on chain." At the time of writing, these coins were still held at that address. In an apparent attempt to initiate communication, a small mainnet transaction to the hacker's address included an OP_RETURN message, "Please contact [email protected]", presumed to be from a Blockstream public address, though this remains unconfirmed. A later OP_RETURN spend from the hacker address carried "Please contact us on Signal @m671aw.70", however, this may be spam and does not share a link to the address with the stolen funds.

In response to the breach, exchanges were instructed to halt L-BTC deposits and withdrawals. While Liquid Network bridge nodes have been paused, limiting access to the sidechain, it continues to produce blocks. Samson Mow, CEO of JAN3, confirmed that Aqua's Liquid features were impacted, but on-chain bitcoin functionality remained operational. The incident is expected to affect other industry wallets utilizing the Liquid Network. Users holding L-BTC now face potential risk, as the underlying BTC is currently not redeemable.

Due to the private nature of the Liquid chain, public on-chain analytics are scarce, making it difficult to ascertain the distribution of L-BTC among retail users, corporations, and Blockstream itself. Should the funds not be recovered, it would constitute a significant setback for the Liquid Network's user base. L-BTC users currently have limited options beyond awaiting the resolution of discussions with the hackers. Given the substantial size of the hack, full evasion for the hackers would be challenging, though not impossible. It is speculated that the hackers might seek a finder's fee in exchange for returning the majority of the funds.

Loading...