A software vulnerability in the Liquid Network allowed attackers to mint unbacked L-BTC. Although the majority of the stolen assets were returned, the hackers kept 598 .5 bitcoin.
The failed patch at block height 4,050,335
The technical failure within the Liquid Network, a Bitcoin sidechain developed by Blockstream, stemmed from a botched attempt to resolve a long-standing issue. According to the report, the network had been carrying a vulnerability related to transaction validation since 2019. A software update released last week was intended to patch this flaw, but it inadvertently introduced a new bug that hackers were able to exploit.
This software error caused a significant divergence in how the network's nodes operated. While some Liquid nodes rejected the exploit transaction, others processed it correctly, causing the network to stall at block height 4,050,335. This discrepancy allowed the attackers to successfully generate Liquid Bitcoin (L-BTC) that was not actually backed by assets on the base Bitcoin blockchain.
A $280 million return and a $47 million theft
The scale of the exploit involved a massive movement of digital assets that briefly threatened the stability of the Liquid Federation . The attackers managed to trigger a peg-out process that released a total of 3,996 bitcoin to their Bitcoin addresses. However, the financial outcome was split between a massive recovery and a significant loss.
As the report indicates , the hackers eventually returned 3,400 bitcoin—valued at approximately $280 million—to the Liquid Federation. Despite this return, the attackers successfully retained 598.5 bitcoin,which is currently worth roughly $47 million. It is important to note that the hack did not involve the compromise of multisig keys on the base Bitcoin blockchain, but rather a failure in the sidechain's internal software logic.
SideSwap's role in the 3,996 BTC peg-out
The execution of the theft relied heavily on the Liquid Network's peg-out mechanism, specifically through the services provided by SideSwap. The Liquid Network is designed to allow assets to move between the sidechain and the main Bitcoin network, but this process is typically restricted to authorized federation members and whitelisted destinations.
In this instance, the unbacked L-BTC created by the hackers was processed throgh SideSwap's peg-out service. This allowed the attackers to convert the fraudulent sidechain tokens into legitimate Bitcoin on the base network, resulting in the federation releasing the 3,996 bitcoin that the hackers initially controlled.
The "decentralization theater" critique of the Liquid Federation
The incident has sparked intense debate regarding the actual security and decentralization of the Liquid Federation, which is composed of various exchanges , trading firms, and wallet providers. Some observers have criticized the current security model, labeling it as "decentralization theater" because of how easily the system was manipulated.
The core of the criticism lies in the fact that a single software update could effectively enable such a massive theft. This has raised serious questions about the effectiveness of the multisig signng process and whether the Liquid Federation's reliance on Blockstream's software development creates a centralized point of failure that undermines the network's purported security benefits.
Verifying the "white hat" claims from the attackers
While the technical details of the exploit are becoming clearer, the motivations of the hackers remain unverified. The attackers have claimed to be "white hat" hackers, suggesting their actions were intended to highlight vulnerabilities rather than purely for theft.. They reportedly attempted to contact Blockstream through embedded messages within Bitcoin transactions to signal their findings.
However, several questions remain unanswered. It is not yet clear if the return of the $280 million was a voluntary act of transparency or a strategic move to avoid more severe legal consequences. Furthermore,the community is still waiting for a full audit to determine exactly how a 2019 vulnerability and a 2024 patch could combine to create such a critical opening.
Comments 0