Liquid Network Breach Exposes Risks of Sidechain Trust
The Liquid Network, a Bitcoin sidechain designed for faster and cleaner transactions, suffered a massive security breach on September 6. Hackers drained nearly $320 million from the network's federation wallet by exploiting a consensus bug in Elements, the software used by Liquid. The bug allowed a party to create around 4,000 L-BTC without making the corresponding bitcoin deposit.
The hackers then sent these tokens to SideSwap's peg-out service, where they were burned as if they were ordinary L-BTC. As a result, about 3,996 BTC was released from the federation wallet to a Bitcoin address.
The next day, September 7, $47 million worth of BTC returned to the Liquid federation address after on-chain messages between Blockstream and the actors who claimed to be white hats. However, about 598.5 BTC remained with the same holder address, which Blockstream refused to pay out due to a lack of agreement for a bounty.
Ledger's chief technology officer Charles Guillemet described this situation as 'straight extortion,' highlighting that honest researchers would have contacted Blockstream's security team first and allowed the network to pause before discussing a bounty.