Liquid Network's $320M Bitcoin Heist Raises Trust Questions
Hackers drain ~95% of Liquid's federation wallet, promise return if bug is fixed, testing sidechain trust.
In a brazen heist that has shaken confidence in Bitcoin sidechains, attackers siphoned roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network — then identified themselves as white-hat hackers seeking to expose a vulnerability. The incident, disclosed Sunday, has left the cryptocurrency community questioning the security of federated sidechains and the true motives of the so-called good guys.
Federation Wallet Nearly Emptied
Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and financial institutions, said in a post on X that around 4,000 BTC had been withdrawn from its federation wallet by what it cautiously described as "purported white-hat hackers." The wallet held about 4,200 BTC before the incident, meaning roughly 95 percent of its holdings were removed in a single blow.
The attack targeted the very mechanism that underpins Liquid's security model. Unlike Bitcoin's proof-of-work consensus, Liquid relies on a federation of functionaries who collectively manage the Bitcoin backing L-BTC. This incident highlights that adding Bitcoin to a sidechain does not automatically inherit Bitcoin's robust security.
Attackers Claim to Be White Hats
The individuals behind the withdrawal have been keen to establish that this is not a typical crypto heist. In a message embedded in a Bitcoin transaction, they identified themselves as "whitehats" and asked Blockstream to get in touch. Blockstream responded on-chain with contact details for its security team, and Liquid said the parties subsequently moved their communications to encrypted channels.
"Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."
— The attackers, in an on-chain message
Those responsible said they would return "most" of the Bitcoin once the vulnerability was fixed and Liquid's nodes had been updated. The promise has done little to calm nerves, as the crypto community debates whether such actions constitute ethical security research or a sophisticated extortion plot.
Technical Mysteries: PAK and SideSwap
Exactly how the attackers managed to move almost the entire federation wallet remains under investigation. Liquid said the BTC was withdrawn through SideSwap using its Peg-out Authorization Key, or PAK, but that neither SideSwap's key nor any other PAK appeared to have been compromised.
PAKs allow federation functionaries to recognize destinations authorized to receive peg-outs; the functionaries collectively release the corresponding Bitcoin. That leaves the critical question of how an apparently authorized SideSwap peg-out could empty nearly the entire wallet without the relevant PAK being compromised. Security researchers are poring over the transaction data to understand the exploit.
Immediate Response: Nodes Disabled
In response to the breach, Liquid disabled its bridge nodes while federation members investigate. The network also asked exchanges to suspend L-BTC deposits and withdrawals, a move that has disrupted trading and highlighted the operational risks of federated sidechains.
The swift action underscores the severity of the incident, but it also reveals the fragility of a system that depends on a small group of functionaries to safeguard billions in assets. Other assets issued on Liquid, including stablecoins, do not appear to have been directly affected, and the Bitcoin network itself was untouched.
Broader Implications for Sidechains
This incident serves as another reminder that adding Bitcoin to something does not give it Bitcoin's security model. Liquid is a federated sidechain whose members collectively manage the Bitcoin backing L-BTC, rather than relying on Bitcoin's miners to secure those funds. This design trade-off offers faster transactions and added functionality but introduces trust assumptions that malicious actors can exploit.
For exchanges and financial institutions that rely on Liquid for settlement, the heist raises serious questions about the resilience of federated sidechains. The attack could prompt a re-evaluation of security practices and accelerate the development of more robust sidechain architectures.
What Happens Next: The Return Promise
For now, those funds appear to be in the hands of people who insist they're conducting security research. Whether all 4,000 BTC eventually find their way home may determine how generous everyone feels about that description. The crypto community watches closely as Liquid works to patch the vulnerability and restore trust.
Why This Matters to You
If you hold L-BTC or use exchanges that depend on Liquid, this event signals that sidechain security is not a guarantee. While the attackers promise to return the funds, the incident highlights the risks inherent in federated models, where a few trusted parties control the keys to your crypto. The fallout could mean stricter security protocols, but it also serves as a warning: the next so-called white hat might not be so benevolent.
Sources
- The Register Original source
Continue Reading
Shadow AI Creeps Past Security Teams
UK NCSC warns employees' unauthorized AI tool use threatens data security.
N-able's Fourth N-central Hotfix Still Leaves Exploitation Question Open
N-able shipped a fourth N-central hotfix for a critical RCE flaw, but its own statements conflict on whether it's been exploited.
UK food chain cyber risks on the rise
National Audit Office warns cyber-attacks threaten food supply, adding to costs and price inflation.