Liquid Network resumes block production after $320M exploit
The Liquid Network resumed block production on Thursday after deploying emergency software updates, though transactions and peg operations remain suspended as a precaution while the network is monitored for full stabilization. The restart follows an incident on Sept. 6 in which roughly 4,000 BTC, worth about $320 million, was withdrawn from the network's federation wallet via a bug in the Elements software.
Liquid is one of the largest and longest-running Bitcoin sidechains, and the withdrawal drained roughly 95% of its federation wallet's balance, exposing how concentrated trust in federated bridge designs can translate into systemic risk. The incident affects L-BTC holders, issuers of tokenized assets and stablecoins on Liquid, and the exchanges and market makers that rely on it for settlement.
The attacker exploited a proof-verification cache vulnerability in Elements' range proofs, allowing the minting of roughly 4,000 unbacked L-BTC that were then redeemed for real BTC through SideSwap's authorized exit peg path. The emergency patch, Elements v23.3.4, hardened the cache keys used for range proofs; after affected bridge nodes were patched, 3,400 BTC (about $270 million) was returned, leaving roughly 598 BTC (about $46 million) outstanding as of Sept. 7.
rss · Cointelegraph · · 3 sources
Background, discussion, and references
Market impact
The transmission channel is peg confidence: with peg operations and PAK-authorized peg-outs suspended, the redemption path connecting L-BTC to BTC is constrained, which bears on venues, issuers and liquidity providers that settle on Liquid, including SideSwap-linked exits. The incident also feeds into a broader reassessment of custody and federation risk across federated Bitcoin layer-2 and bridge designs, and the outstanding ~598 BTC shortfall in the BTC/L-BTC reserve is the key variable still being resolved.
Background
Liquid is an open-source Bitcoin sidechain launched by Blockstream in 2018 that enables faster, more confidential BTC transfers and the issuance of digital assets such as stablecoins, tokenized securities and bonds. Users hold L-BTC, which is pegged 1:1 to BTC and backed by real bitcoin locked in a wallet collectively managed by federated nodes called functionaries. Elements is the open-source codebase underpinning the network, and its Confidential Transactions feature uses range proofs to validate that transaction amounts are legitimate without revealing them publicly; a flaw in the caching of those verifications is what the attacker exploited.
References
Tags
#liquid-network#exploit#bitcoin-sidechain#security-incident#blockchain-recovery