$320M Liquid Network Hack Exposes Proof-Verification Cache Flaw
A hack of the Liquid Network led to the withdrawal of around $320 million in Bitcoin from its federation wallet. On September 6, actors claiming to be white-hat hackers exploited a bug in Elements, the open-source software powering Liquid, allowing them to create unbacked L-BTC.
The flaw, which sat in the proof-verification cache, let the actor reuse valid proof results where they should have failed. This enabled them to submit unbacked L-BTC through SideSwap's authorized peg-out service, draining the federation wallet from about 4,205 BTC down to around 202 BTC.
Blockstream and the actors communicated through messages embedded in Bitcoin transactions, with the actors agreeing to return the funds after nodes were patched. After Blockstream confirmed its bridge nodes had been fixed, the actors returned 3,400 BTC, worth around $270 million at the time, restoring about 85% of the withdrawn funds.
Around 598 BTC, worth roughly $46 million, remains in the withdrawal-linked address with no public agreement confirming whether this is an approved bounty or when it might be returned. Ledger's Chief Technology Officer Charles Guillemet publicly questioned the white-hat label, suggesting that keeping around 600 BTC without disclosed terms looked more like extortion than a standard security reward.