Liquid Bitcoin Sidechain Hack Triggers Emergency Pause

Blockonomics
Blockonomics


Roughly 4,000 Bitcoin, worth around $320 million, vanished from a wallet tied to Blockstream’s Liquid Network over the weekend, triggering an emergency pause of the sidechain and a scramble across exchanges to protect users. The Liquid Bitcoin sidechain hack — if that’s even the right word for it — appears to be the work of self-described white hat actors who say they intend to give most of the funds back once a software flaw is fixed. For now, the network remains frozen, and the crypto industry is watching closely to see whether that promise holds.

Key takeaways

  • About 4,000 BTC — roughly 95% of the wallet’s approximately 4,200 BTC balance — was withdrawn from Liquid before the sidechain was paused.
  • Purported white hat hackers say they will return most of the funds once the underlying Elements vulnerability is patched network-wide.
  • Liquid disabled bridge nodes to block new transactions, and several exchanges halted or prepared to halt L-BTC deposits and withdrawals.
  • SideSwap confirmed its Peg-out Authorization Key was not compromised; the exploit stemmed from a bug in the open-source Elements software.
  • Other assets on the Liquid network, including USDT, DePix, and tokenized real-world assets, were unaffected.

Liquid Sidechain Pauses After Major Bitcoin Withdrawal

Liquid’s federation moved to freeze the sidechain on Sunday after detecting the massive outflow, cutting off new transactions network-wide while teams assessed the damage. The decision came fast, and it needed to — nearly all of the wallet’s holdings were already gone by the time the alarm went off.

Scale and Impact of the Withdrawal

The numbers tell the story on their own. The withdrawn Bitcoin represented roughly 95% of the wallet’s approximately 4,200 BTC balance before the incident, according to details shared by Blockstream and reported by Cointelegraph. That’s not a partial breach or a test transaction — it’s close to a full drain of the affected wallet, which explains why the Liquid bridge pause was treated as an emergency rather than a routine maintenance window.

Effect on Other Assets

Not everything on Liquid was caught in the fallout. Liquid said other assets issued on the network — including USDT, DePix, and various real-world assets — were unaffected by the incident. That distinction matters: it suggests the vulnerability was specific to how Bitcoin moves through the sidechain’s peg mechanism, rather than a flaw touching the broader token ecosystem built on top of it.

okex

White Hat Hackers Exploit Elements Vulnerability

The actors behind the withdrawal have identified themselves, at least implicitly, as white hats — hackers who exploit a flaw not to steal funds outright but to force a fix, often with a promise to return what they took. Whether that promise is honored here remains an open question, but the early signals point toward cooperation rather than confrontation.

Actors’ Intent and Communication

Blockstream, Liquid’s core technology provider, began reaching out to the actors through signed onchain messages shortly after the withdrawal was discovered. According to Cointelegraph, subsequent exchanges showed the actors telling Blockstream to patch the vulnerability and confirm that every node on the network had been updated before they would return the funds. That’s a notable condition — it ties the return of the Bitcoin directly to the security of the entire federation, not just a single fix.

Galaxy Digital research head Alex Thorn noted that the actors also sent encrypted technical details to Blockstream to help identify and patch the flaw. As of the latest reporting, the funds had not yet been sent back.

Role of SideSwap and Technical Details

SideSwap, a Liquid-based exchange service, moved quickly to clarify where the bug actually lived. The company indicated that the withdrawal was processed via its peg-out service, submitted as a customer order with its Peg-out Authorization Key, but stressed that the key itself was never compromised. Instead, SideSwap stated that the L-BTC involved in the transaction came from a flaw within Elements, which is open-source software that underpins Liquid — rather than from any weakness in SideSwap’s own systems. That detail helps narrow the blast radius of the Elements vulnerability to the sidechain’s core code rather than to any single exchange integration.

Operational Response and Network Status

Liquid’s response followed a familiar playbook for sidechain emergencies: cut off new transactions first, communicate second, patch third. Bridge nodes were disabled to prevent further transactions from moving through the network, effectively freezing the sidechain in place while engineers worked to understand the full scope of the flaw.

Bridge Nodes Disabled and Exchange Reactions

Exchanges that support L-BTC trading didn’t wait around for a full explanation. Several had already halted or were preparing to halt deposits and withdrawals of L-BTC as news of the withdrawal spread, a defensive move aimed at limiting exposure while the situation remained unresolved. For platforms and traders relying on Liquid’s rails, that pause translates directly into frozen liquidity — a real cost even if the underlying funds eventually come back.

Federation’s Fix Efforts and Sidechain Status

Federation members were working to fix the vulnerability while the sidechain remained paused, though no timeline had been given for when normal operations might resume. This is where the story matters beyond the immediate dollar figure: Liquid operates as a federated sidechain, meaning its security depends on a group of trusted signers rather than a single validator, and a bug at the Elements software level threatens the trust model that underpins the entire network — not just one wallet.

That’s also why the white hats’ insistence on a network-wide patch, rather than a quiet fix, carries weight. If every node needs updating before funds move again, the incident becomes as much a coordination problem as a technical one, and it explains why exchanges chose caution over business as usual.

The situation remains fluid. Blockstream has not issued a full public statement detailing the exploit’s complete scope, and it’s still unclear exactly when the paused bridge will reopen or whether the withdrawn Bitcoin will be returned in full. What’s clear is that the episode puts a spotlight on how quickly liquidity can lock up when a sidechain’s core software shows a crack — even one that its finders say they want to help repair.

FAQ

How much Bitcoin was withdrawn during the Liquid Network incident?

About 4,000 BTC, representing approximately 95% of the wallet’s balance, was withdrawn.

Who executed the withdrawal of Bitcoin from Liquid Network?

Purported white hat hackers executed the withdrawal and have stated their intent to return most funds after a patch.

What measures were taken by Liquid Network in response to the incident?

Bridge nodes were disabled to prevent new transactions, and exchanges halted or prepared to halt L-BTC deposits and withdrawals.

Was the SideSwap Peg-out Authorization Key compromised in the exploit?

No, SideSwap confirmed their Peg-out Authorization Key was not compromised; the exploit was due to a bug in the Elements software.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*