The Liquid Network, a Bitcoin sidechain developed by Blockstream, was drained of roughly 4,000 bitcoin worth about $320 million on Sunday. The person or people behind the exploit said they were white hat hackers and communicated with Blockstream through messages embedded in Bitcoin transactions using OP_RETURN. The attackers have since returned 3,400 bitcoin to the Liquid federation, while keeping 598.5 bitcoin (currently worth around $47 million). The incident does not appear to have involved compromised keys from the multisig address that underpins the network on the base Bitcoin blockchain. Instead, an apparent bug in Liquid’s node software allowed attackers to create unbacked Liquid Bitcoin (L-BTC) and then use those coins to trigger a legitimate-looking peg-out from the sidechain back to Bitcoin’s base network. What Is the Liquid Network? Liquid is a sidechain designed to move bitcoin and other assets onto a separate blockchain with faster transactions and additional features, including more private transactions and asset issuance. It is operated by the Liquid Federation, a group of Bitcoin-focused companies that includes exchanges, trading firms, wallet providers, and other infrastructure businesses. Blockstream develops much of the network’s software and works with the federation on its technical roadmap. When someone moves bitcoin onto Liquid, the bitcoin is locked in a federation-controlled wallet and an equivalent amount of Liquid bitcoin, or L-BTC, is created on the sidechain. Liquid is operated by a federation of more than 80 members, but only 15 currently operate the specialized functionaries at the heart of the network. Those functionaries both produce and sign Liquid blocks and secure the bitcoin held in the federation’s 11-of-15 multisig wallet on the base Bitcoin network. How the $320 Million Exploit Worked The technical details of what happened are somewhat complicated, but the basic gist is that a software bug caused some Liquid nodes to accept a transaction that created more L-BTC than the system actually had backing for. According to a summary posted to X by pseudonymous Bitcoin industry developer Mononaut, Liquid originally introduced a vulnerability related to the cryptographic proofs used to validate transactions in 2019. Last week, developers attempted to fix that issue via a software update. However, that update also apparently introduced a new bug. There's some confusion about what, exactly, was exploited here. I've seen claims that this was a long-standing bug, exploited after the "fix" was pushed to the open source repo but before that fix could be rolled out in production. That does not appear to be true. Instead, it… https://t.co/TJeSL7g6kb pic.twitter.com/TazXXpjzWv — mononaut (@mononautical) September 7, 2026 On Sunday, attackers exploited that flaw. Nodes vulnerable to the bug in the updated software treated the transaction as valid, which allowed the attacker to effectively create roughly 4,000 unbacked L-BTC. Some Liquid nodes were apparently running official software versions that did not contain the new bug. Those nodes rejected the exploit transaction and stalled at block height 4,050,335. However, the relevant nodes involved with the peg out process were, unfortunately, running the new software. The newly created L-BTC was then sent through SideSwap for the peg-out process, and the federation ultimately released roughly 3,996 bitcoin to a Bitcoin address controlled by the attacker. The Liquid Network’s official X account posted that the SideSwap authorization key and the federation’s other keys were not compromised during the attack. The signers did exactly what they were supposed to do because the software told them the peg-out was legitimate. SideSwap’s role in the incident is also drawing scrutiny because Liquid’s peg-out system is designed to restrict withdrawals to authorized federation members and whitelisted Bitcoin destinations. In this case, however, roughly 4,000 newly created L-BTC was processed through SideSwap’s peg-out service, resulting in the federation releasing 3,996 bitcoin to the attacker’s Bitcoin address. Bitcoin security researcher and Liquid member Wiz argued, “If Sideswap broke this strict security policy, whereby members are only allowed to peg-out to offline cold storage, they are partly responsible for the theft.” Other sidechain proposals have attempted to address this kind of problem with time delays. Systems such as Drivechains and Rootstock have mechanisms intended to give operators more time to identify and stop suspicious withdrawals before funds leave the system. Notably, a somewhat similar bug regarding the potential creation of fake cryptocurrency appeared in Zcash earlier this year. A vulnerability in its Orchard shielded transaction system could theoretically have allowed unauthorized creation of ZEC. It was the second such vulnerability with the potential to enable hidden inflation to be discovered in Zcash’s history. Everyone has to install it themselves so it's better than one person push. But no one validated shit. Federation would have just installed code that sent to blockstream devs private wallet if they were told. — alp (@alpacasw) September 7, 2026 The ability for a code update from a single party to effectively enable this recent theft of the bitcoin that backed the Liquid Network has led some to criticize the sidechain’s security model as decentralization theater. Bitcoin Core contributor Michael Folkson summarized the criticism bluntly on X, posting, “So as I claimed before it is effectively single sig. Whoever writes and pushes the ‘if valid…’ code can move the funds. The actual multisig signing is security theater.” This concept of decentralization theater has been a growing criticism of the crypto space in general in recent years, as stablecoins, corporate blockchains, and other points of centralization have led to the industry looking more and more like the traditional financial system over time and created a crisis of purpose for decentralized general-purpose blockchains. The Liquid Network also had an earlier warning about the complexity of its security architecture. In 2020, a timelock bug made roughly 870 bitcoin accessible through an emergency 2-of-3 multisig rather than the normal 11-of-15 federation arrangement. The funds were never stolen, and Blockstream patched the issue, but the incident demonstrated that the sidechain’s security model relies on more than the 15-member federation. White Hats or Something Else? It remains unclear who is behind the exploit, but on X, Ledger CTO Charles Guillemet wrote, “They don’t seem to be white hats, and they don’t seem to be the usual criminals either.” The attackers repeatedly described themselves as white hats and demanded that the vulnerability be fixed before returning most of the bitcoin, but according to Gart founder Alena Vránová, that does not necessarily protect them from legal consequences. “If you exploit vuln, steal 4k BTC and demand a fix for ransom, that’s EXTORTION,” Vránová posted on X. “This can mean felony charges and long prison time. In the U.S. up to 20 years, and computer-fraud charges can add more.” Blockstream eventually told the hackers that the relevant bridge nodes had been patched, and the hackers were careful to confirm the correct address for returning the funds. Near the end of their back and forth via OP_RETURN transactions, the entirety of the messages posted to the blockchain were encrypted via PGP. Eventually, the attacker sent 3,400 bitcoin back to the Liquid federation address and kept 598.5 bitcoin, or roughly 15% of the amount initially withdrawn, for themself. Source: Mempool.space It is currently unclear whether AI played a role in discovering the vulnerability, but crypto has become increasingly exposed to AI-assisted hacking this year. April was the worst month on record in terms of the sheer number of crypto hacks taking place, with nearly one incident occurring per day. On X, Mempool’s Orangesurf claimed that Fable 5 could identify the vulnerability behind the Liquid exploit with a five-word prompt. How Long Can Bitcoin Remain Secure? Liquid was developed by a company whose founders include some of the earliest Bitcoin developers and Satoshi candidate Adam Back, and the incident comes alongside other recent vulnerabilities affecting highly trusted Bitcoin-related infrastructure, including a vulnerability exploited for more than $100 million worth of bitcoin in the Coldcard hardware wallet. So far, Bitcoin’s base blockchain and Bitcoin Core software have remained untouched by this greater wave of exploits hitting crypto. But recent events have some questioning how long that will continue. As Japanese Bitcoin researcher and educator Koji Higashi put it in a translated X post, “Bitcoin’s [base blockchain] itself isn’t affected at the moment, but if a major vulnerability were to be found even there, it’d be seriously bad, so that part absolutely needs to be defended to the death.” The bigger problem for Liquid may be what happens now that a large portion of the bitcoin has been returned. Liquid main trust assumption was based on the fact that it ran for 8 years with some unnamed functionaries (on purpose! to not make it a chokepoint). so, whether the funds for liquid get returned or not, there won't be a running Liquid anymore, ie: whether the "whitehats" is… — Nicolas Burtey (@nicolasburtey) September 6, 2026 Cake Wallet COO Seth for Privacy captured the key question now hanging over the project in an X post, asking, “I think an unspoken critical problem in all this is . . . who is going to trust Liquid with their money?” Galoy founder and CEO Nicolas Burtey went even further, writing that regardless of whether the funds came back, “they’ve killed Liquid.”
Hackers Drain $320 Million From Bitcoin’s Liquid Network, Keep $47 Million for Themselves in ‘White Hat’ Operation
Full Article
Original Source
Read the full article at Gizmodo →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.