Liquid Network hackers steal $320M in Bitcoin, return most after patch
Attackers exploited a vulnerability in Liquid Network's Elements software to mint unbacked L-BTC and drained roughly 4,000 BTC (~$320 million) from its reserve. About 3,400 BTC were returned on Sept. 7, and Blockstream is negotiating to recover the remaining ~600 BTC after patching bridge nodes and preparing an emergency update.
This is one of the largest exploits involving a Bitcoin sidechain and directly tests how much trust users place in federated pegs and wrapped Bitcoin products. It shows that transaction-validation failures can jeopardize user funds even when no private keys or federation nodes are compromised.
Liquid's reserve fell from about 4,205 BTC to 197 BTC before operations were halted; Liquid said USDT and other Liquid-issued tokens were unaffected by the vulnerability, though users could not transact during the pause. The validation failure occurred at the transaction level before the peg-out was initiated, so SideSwap's node and Liquid's distributed functionary nodes accepted the unbacked L-BTC, and roughly 600 BTC (~$47 million) remains outstanding.
gdelt · siliconangle.com · · 6 sources
Background, discussion, and references
Market impact
The incident directly touches the peg and redemption infrastructure for L-BTC and Liquid-issued assets, so institutions and exchanges relying on Liquid may face liquidity and trust frictions. Market effects, if any, would flow through custody and validator-settlement confidence rather than the Bitcoin base chain; further impact depends on the final recovery and network restoration, not any predetermined direction.
Background
The Liquid Network is a Bitcoin sidechain run by the Liquid Federation, in which a distributed set of functionary nodes manages the mainchain and sidechain. To use it, users send real BTC in a peg-in transaction and receive L-BTC, an asset designed to be backed 1:1 by Bitcoin held by the federation. Peg-out mechanisms allow whitelisted addresses to redeem L-BTC for the reserve Bitcoin. In this incident, the flawed L-BTC was created through a bug in Elements, the open-source software powering Liquid, and then swapped through SideSwap for real BTC.
Discussion
Commentary focused on skepticism about the white-hat designation: Ledger CTO Charles Guillemet called the decision to keep 600 BTC more like extortion than white-hat hacking. The broader discussion also noted that the returned BTC alone does not guarantee full L-BTC backing or restored withdrawal and redemption access while bridge nodes remained down.
References
Tags
#security#bitcoin#Liquid Network#exploit#recovery