$320M Liquid Network Exploit Patched, Funds Safe for Return
Blockstream's Liquid Network suffered a significant loss on September 6 when an attacker exploited a bug in the Elements software, draining approximately 4,200 BTC from the federation's wallet. The attack was made possible by a vulnerability in the peg-out mechanism for L-BTC, which allowed the attacker to convert invalid L-BTC back into native BTC on the main Bitcoin blockchain.
The resulting loss was catastrophic, with the federation's reserves plummeting from over 4,200 BTC to around 197 BTC. However, Blockstream moved quickly to contain the damage, disabling bridge nodes, pausing network activity, and instructing exchanges to suspend L-BTC deposits and withdrawals.
Fortunately, no PAKs or federation keys were compromised in the attack, which was entirely a software bug rather than a breach of the cryptographic keys that govern the network's multi-signature security model. Blockstream exchanged messages with the attacker via PGP-signed OP_RETURN transactions on the Bitcoin blockchain, confirming that the patches were in place and encouraging the prompt return of funds.