Liquid Hack Exposes Weakness in Bitcoin Sidechain's Withdrawal System
The Liquid Bitcoin sidechain was recently exploited for approximately $318.7 million when hackers created 4,000 L-BTC tokens without any backing of real Bitcoin.
Liquid's system is designed to ensure that even if federation operators are compromised, users' funds cannot be redirected to attacker-controlled addresses.
Alex Thorn, head of firmwide research at Galaxy Digital, stated on Unchained's Uneasy Money podcast that the restriction never bound the people who took roughly 4,000 BTC. According to Liquid's documentation, most users cannot make the swap themselves and must go through a federation member or exchange instead.
The attackers used a workaround by going through SideSwap, which will let anyone show up with an address and withdraw from Liquid and auto-forward it to whatever address the customer supplies. The withdrawal system itself held, according to both companies, and no key was compromised, including SideSwap's.