Blockstream's Liquid Network Suffers $320 Million Hack, Funds Expected to Be Returned
Blockstream's Liquid Network faced a major security incident on September 6, when hackers withdrew nearly 4,000 Bitcoin, worth approximately $320 million, from the Liquid Federation wallet. The exploit was attributed to a vulnerability in the Elements software, which allowed the attacker to initiate a peg-out transaction using invalid Liquid Bitcoin (LBTC).
According to reports, the withdrawal was executed with the approval of 11 out of 15 federation keys, despite the fact that the tokens used for the peg-out should not have existed. The hacker, who claimed to be a white-hat, communicated through OP_RETURN messages on the Bitcoin blockchain, indicating a willingness to return the stolen funds once security measures were confirmed.
In response to the incident, Blockstream promptly disabled bridge nodes and paused network activity to prevent further losses. They also instructed exchanges to halt all LBTC deposits and withdrawals. As of September 7, Blockstream confirmed that the bridge nodes had been patched, paving the way for the potential return of the stolen funds.
Despite the significant loss in BTC reserves, other assets on the Liquid Network, including USDT and DePix, were reported to be unaffected. The incident has raised concerns about the security and functionality of the Liquid sidechain, with discussions ongoing about the implications of the exploit.
Updated 13:31 UTC
New Insights on Liquid Network Hack
- Researchers have identified a failure in the software’s transaction-validation cache as a key factor in the $320 million hack.
- Allegations suggest that unbacked tokens were redeemed for real Bitcoin due to a bug that had entered Elements’ master development branch shortly before the incident.
- It was noted that the exploited code was not part of any tagged release, leading to questions about the deployment process.
- Liquid’s federation functionaries reportedly accepted the exploit transactions, while other nodes rejected them, indicating a divergence in software versions.
- A flaw involving range proofs allowed an attacker to create invalid outputs that bypassed necessary checks, leading to the unauthorized withdrawal of Bitcoin.
- Whitehat hackers currently hold the drained Bitcoin and are willing to return the funds once the bug is fixed across all affected nodes.
Updated 14:02 UTC
Latest Developments on Liquid Network Incident
- Liquid Network has paused operations following a purported $320 million withdrawal from multisig reserve addresses.
- The withdrawal was claimed to be a white-hat rescue related to a suspected security flaw.
- Bitcoin mainnet operations were not affected; Bitcoin blocks continued to produce normally during the incident.
- Liquid is a Bitcoin sidechain designed for faster settlements and confidential transactions, operating under a federation model.
- The pause in Liquid's operations is a significant disruption for users and developers relying on the network.
- Operators are expected to release a full incident report detailing the circumstances of the withdrawal and the security issues involved.
- The situation remains sensitive, and the white-hat claim requires careful verification before being accepted as fact.
- Users are advised to wait for clarity before moving assets or relying on the settlement until normal operations resume.
FAQ
What happened to Blockstream's Liquid Network?
Blockstream's Liquid Network experienced a significant security breach on September 6, resulting in the withdrawal of nearly 4,000 Bitcoin, valued at approximately $320 million, from the Liquid Federation wallet.
How did the hackers exploit the Liquid Network?
The hackers exploited a vulnerability in the Elements software that allowed them to initiate a peg-out transaction using invalid Liquid Bitcoin (LBTC), gaining approval from 11 out of 15 federation keys.
What measures did Blockstream take in response to the hack?
In response to the hack, Blockstream disabled bridge nodes, paused network activity to prevent further losses, and instructed exchanges to halt all LBTC deposits and withdrawals.
Will the stolen funds be returned?
The hacker, who claimed to be a white-hat, indicated a willingness to return the stolen funds once security measures were confirmed, and Blockstream has patched the bridge nodes, which may facilitate the return.
Were other assets on the Liquid Network affected by the hack?
No, other assets on the Liquid Network, such as USDT and DePix, were reported to be unaffected by the hack.
Comments
Comments are moderated before publish.
No comments yet — be the first.