Someone Just Walked Off With 95% of Liquid Network's Bitcoin and Wants a Pat on the Back
Around $320 million worth of Bitcoin has been pulled out of the Liquid Network's federation wallet by a group claiming they did it for everyone's benefit. Whether you find that reassuring probably depends on how much Bitcoin you had sitting there.
Liquid, a Bitcoin sidechain built by Blockstream and used primarily by exchanges and trading firms, confirmed on Sunday that approximately 4,000 BTC had been drained from its federation wallet. The attacker or attackers left behind only a sliver of the original 4,200 BTC balance. Blockstream described the culprits as 'purported white-hat hackers,' which is doing some heavy lifting as corporate understatement goes.
The people responsible seem eager to frame this as responsible disclosure with extra steps. They embedded a message in a Bitcoin transaction identifying themselves as whitehats and instructing Blockstream to patch the vulnerability before they'd hand anything back. Blockstream replied on-chain with its security team's contact details, and both sides have since taken the conversation to encrypted channels. The hackers say they'll return 'most' of the Bitcoin once the bug is fixed and nodes are updated.
'Most' is doing a lot of work in that sentence.
Liquid has shut down its bridge nodes while the federation investigates, and exchanges have been asked to pause L-BTC deposits and withdrawals in the meantime. Other assets on the network, including stablecoins, appear unaffected. Bitcoin itself is obviously fine.
The mechanics of the exploit remain opaque. Liquid says the withdrawal went through SideSwap using a Peg-out Authorization Key, the mechanism that lets federation members confirm destinations are authorised to receive Bitcoin from the wallet. The strange part is that neither SideSwap's key nor any other PAK appears to have been compromised. How an apparently legitimate peg-out request managed to drain nearly the entire wallet without a key being touched is precisely what investigators are trying to work out.
This is also a timely reminder that wrapping Bitcoin inside a federated sidechain is not the same thing as Bitcoin security. Liquid's backing funds are controlled collectively by federation members, not by Bitcoin's proof-of-work. That's a fundamentally different trust model, and this incident underscores the gap.
For now the funds are with people who claim good intentions. Whether all 4,000 BTC makes it back will say rather a lot about how seriously that claim should be taken.