Liquid Network Hackers Drain $320M, Return Most After Patch
The Liquid Network, a prominent Bitcoin sidechain, suffered a significant security breach on September 6. Hackers exploited a bug in its underlying Elements software and drained approximately 4,000 BTC (valued at $320 million) from the federation wallet. The federation's reserves plummeted to around 197 BTC.
Fortunately, the attackers identified themselves as white-hat hackers and returned about 3,400 BTC after Blockstream confirmed it had patched the vulnerability. They retained approximately 598 BTC ($47 million) as a self-appointed bounty.
The bug in question affected the validation of Liquid Bitcoin (L-BTC) tokens, which allowed the attackers to create invalid tokens that were processed through SideSwap's Peg-out Authorization Key (PAK). This converted them into real BTC withdrawals from the federation wallet. No federation keys were compromised during the attack, as the 11-of-15 multisig model held up fine.
The incident raises questions about federated sidechain architecture and the trust placed in a relatively small group of entities to secure the bridge between Bitcoin's main chain and the sidechain. The Elements codebase, used by Liquid and other projects, clearly needed more rigorous review of its verification logic to prevent similar vulnerabilities.