$320 Million Worth of Bitcoin Disappeared from Liquid. The Attacker Claims They Will Return It

Liquid Network has suffered an extremely serious security incident. Nearly 4,000 BTC worth around $320 million left the system, with the person controlling the funds subsequently identifying themselves as a “white hat” hacker. According to their statement, they want to return the bitcoins only after developers fix the bug that enabled the massive withdrawal. Operation of the bridge between Liquid and the Bitcoin network therefore remains restricted.

Don’t miss: Binance seeking new MiCA license in EU

Nearly the entire Bitcoin reserve left in a single withdrawal

The incident began on September 6, when a customer requested a withdrawal of 4,000 L-BTC through SideSwap’s peg-out service. The system evaluated the request as a regular transaction, burned the L-BTC tokens, and subsequently released approximately 3,996 BTC into the main Bitcoin network. After accounting for a previous transaction, the destination address contained approximately 3,998.5 BTC, while the system’s reserve dropped to approximately 197 BTC.

Current information does not suggest a classic theft of signing keys. A valid Peg-out Authorization Key from SideSwap was used, which according to available statements was also not compromised. The problem is believed to be related to a bug in the Elements software on which Liquid operates. This allowed the system to accept L-BTC that were not created through standard means, and subsequently process their withdrawal as a legitimate request.

Read more: Anycoin review

“White hat” communicates via blockchain, but bitcoins haven’t been returned yet

Several hours after the transaction, a message appeared on the blockchain stating “we are whitehats. contact us on chain.” Blockstream subsequently responded in the same manner and published contact information for its security team. Communication between both parties continued using signed messages, and the holder of the funds eventually stated they are prepared to return most of the bitcoins. The condition is that the bug must first be fixed and affected nodes updated.

The incident also demonstrates the limits of multisig security. According to current information, the 11-of-15 signature system was not breached – the signatures merely approved a transaction that the software mistakenly considered legitimate. A strong multisig solution can thus protect against key theft, but not against a bug in the system logic that determines what should be signed in the first place. Blockstream, the company behind Liquid Network, is now addressing not only the bug fix itself, but also restoring trust in the system’s infrastructure. As of September 7, approximately 3,998.5 BTC remained at the same address, so the “white hat” designation currently rests solely on the claim of the person or group controlling the funds.

Don’t miss: MadisonSix

author avatar
Hynek Král
Hynek Král is an independent analyst and investor specializing in the cryptocurrency ecosystem, with a primary focus on Bitcoin (BTC) and Ethereum (ETH). His work effectively bridges the gap between current market news, in-depth technical analysis, and practical professional trading strategies.