$320M Hack Exposes Liquid Network's Confidential Transactions Weakness
A critical vulnerability in Liquid Network's Confidential Transactions system allowed hackers to drain nearly $320 million worth of BTC on September 6. The attackers exploited a flaw in the caching mechanism for cryptographic proofs, enabling them to mint unbacked L-BTC tokens and swap them for actual BTC.
The breach targeted Liquid Network, developed by Blockstream, which provides fast, low-cost, and private Bitcoin transactions using L-BTC tokens pegged 1:1 to BTC. Approximately 3,998 BTC, 95% of Liquid's federation wallet, was stolen before the network was paused.
The attackers, claiming to be white-hat hackers, communicated with Blockstream via Bitcoin's OP_RETURN field and pledged to return the stolen funds once the vulnerability was patched. On September 7, Blockstream confirmed the exploit was fixed, and the attackers returned 3,400 BTC in a single transaction.