Over the weekend, attackers exploited a vulnerability in Liquid's Elements software to mint unbacked L-BTC , siphoning approximately $320 million in value. While some funds were returned, the culprits have rettained nearly 600 bitcoin and are demanding a 10 percent payout from Blockstream.

Advertisement

The $320 million drain through SideSwap

The Liquid network exploit highlights a growing vulnerability in sidechain architectures that rely on federated multisig signers.. This incident echoes previous large-scale DeFi hacks where software flaws allowed for the "infinite minting" of assets, placing the burden of security on a small group of validators rather than a decentralized pool.

The breach began when a flaw in the Elements node software allowed for the creation of unbacked L-BTC coins. As the report states, the attackers used the SideSwap platform to cash out roughly 4,000 bitcoin, totaling nearly $320 million in cumulative value. SideSwap has since admitted to procedural fialures, specifically noting that it did not perform checks on the size, velocity, or origin of the orders using its peg-out authorization key.

A 10 percent bounty demand against $5 billion in assets

The attackers have moved from encrypted channels to plain-text demands on the Bitcoin blockchain. They have accused Blockstream of gross negligence, claiming the company allocated only $1.5 million to protect $5 billion worth of assets. According to the source, these individuals are now demanding a 10 percent bounty, threatening a 15 percent loss for all holders if Blockstream does not comply with their terms.

Elements v23.3.4 and the return of 3,400 bitcoin

In response to the breach, Blockstream issued an emergency release of Elements v23.3.4 to fix cache key handling for range proofs. While the attackers returned approximately 3,400 bitcoin once the patch was applied, they have kept roughly 598.5 bitcoin, valued at about $47 million. The official recovery plan involves locking peg operations and validating all replay transactions to restore the network state and return marked funds.

The OP_RETURN "white-hat" claim and the threat of extortion

Several critical questions remain reggarding the attackers' true intentions and the security of the Liquid network. it is currently unclear if the attackers' self-identification as "white-hat hackers" in an OP_RETURN record holds any merit, or if their public ultimatum is purely a tool for coercion. Furthermore, the community is left wondering if Blockstream will succumb to the extortion or if the remaining $47 million in stolen bitcoin will be permanetnly lost to the attackers' wallets.