On Sunday, the Liquid Network reported that alleged white-hat hackers managed to withdraw approximately 4,000 Bitcoin, equivalent to around $320 million, from the federation wallet that supports L-BTC. The bridge nodes were disabled, and the sidechain was paused temporarily. As per the official account on X, other issued assets, including USDT, DePix, and RWAs, remained unaffected by this incident.
The Liquid Network, established by Blockstream under the leadership of Adam Back, serves as a federated sidechain of Bitcoin. This chain facilitates the issuance of various assets, including L-BTC, which is backed by Bitcoin on the main chain. These assets are safeguarded in a multisignature wallet operated by 15 verified corporate members. In order to authorize a transaction from the treasury, at least 11 of these members are required to co-sign. Prior to the hack, the treasury held over 4,200 BTC; however, Blockstream’s proof of reserves page now indicates a remaining balance of just over 207 BTC.
The hackers executed a peg-out transaction, withdrawing 4,019.4 BTC from the reserve address using the SideSwap Peg-out Authorization Key, with SideSwap being a bridge exchange and member of the Liquid Federation. Although the specific mechanics of the hack remain unverified, initial assessments suggest that the perpetrators exploited an inflation bug within the LBTC sidechain, enabling them to generate over 4,000 LBTC that did not previously exist. They then cashed out these assets for on-chain Bitcoin from the federation. Due to a consensus error, the withdrawal transaction appeared legitimate, thereby securing the approval of the federation members’ HSM security servers for the Bitcoin withdrawal, which was valued at approximately $320 million at the time.
The hackers subsequently transferred the funds to an address ending in 6gyqjlte, from which they swiftly executed a new transaction. This transaction included a message in the OP_RETURN arbitrary data field stating, “we are whitehats. contact us on chain.” As of this writing, those coins remained at the specified address.
Following these developments, a minor mainnet transaction was sent to the hacker’s address, including an OP_RETURN message that read, “Please contact [email protected],” presumably from a public Blockstream address, although this remains unverified. Additionally, a later OP_RETURN spend from the hacker’s address requested contact via Signal at “@m671aw.70”; however, this could potentially be spam and does not provide a link to the address containing the stolen funds.
In the wake of this breach, exchanges were advised to halt L-BTC deposits and withdrawals. The bridge nodes on the Liquid Network have also been paused, restricting access to the sidechain, which continues to generate blocks.
JAN3 CEO Samson Mow stated that Aqua’s Liquid features were impacted, though on-chain Bitcoin transactions remained functional. Other industry wallets utilizing the Liquid Network are likely to face similar challenges. Users holding L-BTC now find their assets at risk, as the underlying Bitcoin is currently not redeemable. Given the private nature of the Liquid chain, data regarding on-chain user analytics is limited, and little public information exists concerning the distribution of LBTC among retail users versus Blockstream’s corporate entities. The failure to recover the stolen funds could represent a significant setback for the Liquid Network’s user base.
For users of LBTC, options are severely limited as they await negotiations with the hackers to seek a resolution. Given the magnitude of the hack, it would be challenging for the perpetrators to liquidate the entirety of the stolen Bitcoin, though it is not entirely impossible. A more plausible scenario might involve the hackers seeking a finder’s fee while returning the majority of the funds.
Thank you for visiting our site. You can get the latest Information and Editorials on our site regarding bitcoins.