Liquid Network Pauses After About $320 Million in Bitcoin Is Withdrawn

Liquid Network Pauses After About $320 Million in Bitcoin Is Withdrawn
Liquid Network Pauses After About $320 Million in Bitcoin Is Withdrawn — SAN FRANCISCO, UNITED STATES — Liquid Network paused new transactions after roughly 4,000 bitcoin worth about $320 million was withdrawn fr...

SAN FRANCISCO, UNITED STATES — Liquid Network paused new transactions after roughly 4,000 bitcoin worth about $320 million was withdrawn from the wallet backing its L-BTC token. The actors claim to be white-hat hackers, leaving both the exploit's cause and ultimate financial loss unresolved.

Liquid Network has paused activity on its Bitcoin-linked settlement network after approximately 4,000 BTC, worth about $320 million, was withdrawn without authorization from the federation wallet that backs Liquid Bitcoin, or L-BTC.

The withdrawal represented roughly 95% of the approximately 4,200 BTC held in the federation wallet before the incident, according to Liquid's account of the breach. The network described those responsible as “purported white-hat hackers,” meaning they claim to have acted to expose or protect against a security flaw rather than permanently steal the assets. That claim has not yet established whether the bitcoin will ultimately be returned.

Blockstream, Liquid's technology provider, has been attempting to communicate with the actors through signed messages embedded in Bitcoin transactions. The network disabled its bridge nodes and exchanges were told to suspend L-BTC deposits and withdrawals while federation members investigate.

The incident therefore presents two separate questions: how approximately $320 million in bitcoin could leave a wallet designed to require distributed authorization, and whether the movement ultimately becomes a permanent financial loss.

Roughly 95% of the federation wallet's bitcoin was withdrawn

The scale of the withdrawal is unusually large relative to Liquid's reserves.

Before the incident, the federation wallet contained approximately 4,200 BTC. About 4,000 BTC were withdrawn, leaving roughly 200 BTC, according to accounts of the incident.

Using those rounded figures, the withdrawal represented approximately 95.2% of the wallet's pre-incident bitcoin, a newsroom calculation. Because the underlying figures themselves are approximate, that percentage should also be treated as approximate.

The transaction does not mean the Bitcoin network itself was hacked.

Liquid is a separate Bitcoin sidechain developed by Blockstream. Users can transfer value between Bitcoin and Liquid, where BTC is represented by L-BTC. Blockstream describes Liquid as a Bitcoin layer-2 designed for digital-asset issuance, confidential transactions and faster settlement.

That distinction is important for users: the incident concerns Liquid's infrastructure and the bitcoin backing L-BTC, not Bitcoin's underlying blockchain consensus or ordinary BTC wallets.

Liquid's normal design requires bitcoin and L-BTC to match one-for-one

The incident is particularly consequential because Liquid's architecture is designed around verifiable backing.

Under normal operation, bitcoin transferred into Liquid is held in a federation-controlled wallet and an equivalent amount of L-BTC can circulate on the sidechain.

Blockstream's documentation says users should be able to cryptographically verify that the quantity of L-BTC on Liquid equals the BTC secured by the Liquid Federation wallet.

The federation wallet normally uses an 11-of-15 multisignature arrangement. Fifteen functionaries hold signing keys, and 11 signatures are required for ordinary withdrawals. The keys are stored in hardware security modules distributed among federation members.

A normal withdrawal, known as a peg-out, also requires L-BTC to be destroyed on Liquid before the corresponding BTC is released on Bitcoin.

Blockstream's documentation says federation functionaries normally verify three things during that process: that the destination is whitelisted, that the corresponding L-BTC has been burned and that the outgoing Bitcoin transaction is valid before signing it.

The security investigation therefore needs to explain how an apparently authorized peg-out could release the bitcoin involved in Sunday's incident.

Liquid says the SideSwap authorization key was not compromised

Liquid's initial account narrows one potential explanation while leaving the central technical question unresolved.

The withdrawn bitcoin moved through SideSwap's Peg-out Authorization Key, or PAK, according to Liquid. But the network said that key — and other federation keys — had not been compromised.

That distinction is significant.

A conventional cryptocurrency theft frequently involves an attacker obtaining a private key and then using that credential to authorize transactions. Liquid's initial statement suggests investigators are looking at something different.

SideSwap said a customer sent it about 4,000 L-BTC at 14:05 UTC Sunday. According to Decrypt's account of SideSwap's explanation, those tokens were burned through a valid authorization process, and roughly 3,996 BTC were paid out about 23 minutes later.

SideSwap has said its own systems were not breached and pointed instead toward a problem involving Elements, the open-source software underlying Liquid. Blockstream had not published a complete root-cause analysis in the sources reviewed for this article.

That means it would be premature to characterize the incident simply as stolen federation keys.

Reports point toward invalidly created L-BTC, but the root cause remains under investigation

More detailed technical reporting indicates the problem may have involved L-BTC that should not have existed.

Protos reported that the transaction received the required 11 valid federation signatures even though the L-BTC redeemed for the underlying bitcoin should not have been validly created. It reported that all 83 inputs to the transaction were spent using the normal 11-of-15 signing path rather than Liquid's emergency recovery mechanism.

SideSwap attributed the problem to an Elements software bug, while Decrypt reported that the apparent exploit allowed unbacked L-BTC to be created and then redeemed through what looked to the federation like a normal peg-out.

Those reports provide a plausible technical direction, but Blockstream has not yet supplied the comprehensive post-incident analysis needed to establish exactly which vulnerability was exploited, when it became exploitable and why existing checks did not reject the transaction.

That technical explanation will be central to determining whether the failure occurred primarily in software validation, federation infrastructure, peg-out authorization or a combination of mechanisms.

The actors say they are white hats and have opened an on-chain dialogue

The identity and intentions of the people controlling the withdrawn bitcoin remain another major uncertainty.

A Bitcoin transaction associated with the incident contained an on-chain message in which the actors identified themselves as white hats and asked to be contacted through the blockchain. Blockstream subsequently responded with contact information, and messages have continued using cryptographic signatures, according to multiple reports.

The Register reported Monday that the actors have indicated they intend to return most of the approximately 4,000 BTC after the vulnerability is fixed.

That statement materially changes how the $320 million figure should be described.

The bitcoin has been withdrawn from Liquid's federation reserves, but the eventual financial loss is not yet known. Calling the entire $320 million permanently stolen would go beyond what has been established while the funds remain identifiable and discussions about their return continue.

The “white hat” description should likewise remain attributed. It is a claim about the actors' intentions, not an independently established fact.

Users cannot rely on normal Liquid operations while the network is paused

The immediate consequence for users is operational.

Liquid temporarily disabled bridge nodes, preventing new transactions from being submitted normally, and exchanges were notified to suspend L-BTC deposits and withdrawals. Liquid described the sidechain as effectively paused until the problem is resolved.

The Blockstream documentation explains why that interruption matters. L-BTC is used not only as Liquid's representation of bitcoin but also to pay transaction fees for transfers of other assets on the network.

Liquid said other assets issued on the network — including USDT, DePix and real-world assets — were not themselves affected by the security incident, according to The Block. But wallets and the ability to transact with those assets can still be affected by the network pause.

Users should therefore distinguish between an asset being directly withdrawn and an asset becoming temporarily difficult or impossible to move because the underlying network has been halted.

The incident tests Liquid's one-to-one backing model

The security event also creates an immediate accounting question around L-BTC.

Blockstream's documentation states that the quantity of L-BTC should always be matched one-for-one by BTC held on the Bitcoin mainchain.

If approximately 4,000 BTC have left the backing wallet while the corresponding Liquid supply remains outstanding, that relationship cannot simply be assumed to remain intact.

Independent monitoring cited by Protos showed approximately 4,205 L-BTC outstanding against about 197 BTC remaining in the federation reserves after the withdrawal.

Those figures imply backing of less than 5% at that snapshot, but they should not be interpreted as a conventional market reserve ratio or necessarily as the network's final financial position. The assets may be returned, the outstanding L-BTC supply may change, and the federation may take remediation measures.

What they demonstrate is why restoring normal transactions requires more than merely restarting servers: Liquid must resolve the security problem and establish how the backing of L-BTC will be restored or otherwise handled.

What investigators still need to establish

Four developments will determine the ultimate significance of the incident.

First is a technical postmortem explaining exactly how the invalid or unauthorized withdrawal became possible despite Liquid's multisignature and peg-out controls.

Second is the disposition of the approximately 4,000 BTC. If the self-described white hats return the assets, the permanent financial loss could be far smaller than the headline value withdrawn.

Third is the treatment of L-BTC holders and the restoration of the one-to-one backing relationship that Liquid's documentation describes.

Fourth is a timetable for restoring transactions, exchange deposits and withdrawals, and bridge-node operations without reopening the vulnerability.

Until those questions are resolved, two descriptions should be avoided: that Bitcoin itself suffered a $320 million hack, and that Liquid has definitively lost $320 million.

What is established is narrower but still substantial: roughly 4,000 BTC left the federation wallet backing Liquid, the network halted normal activity, and the security model protecting its Bitcoin reserves is now under investigation.

Keep comments relevant and respectful. Do not post spam, threats, personal information, copyrighted material without authorization, or unsupported allegations. Comments may be moderated or removed.

Previous article Next article

ads

ads

Contact