- The Liquid Network exploit resulted in roughly $320M worth of Bitcoin being withdrawn, highlighting major concerns around Bitcoin sidechain security
- The Liquid $320M hack did not involve a compromised private key, putting the focus on Liquid Network security and the vulnerability in its underlying software
- The incident has raised fresh questions around Liquid token (LBTC) security and how safely Bitcoin-backed assets can operate across sidechain infrastructure
A Bitcoin sidechain designed to make transactions simpler and faster has suddenly become a center of heated debate. On September 6, Liquid Network suffered a major security exploit, as roughly 4,000 BTC worth about $320M was withdrawn from the Liquid Network’s Federation wallet. The incident resulted in the platform pausing its network activity to investigate what had truly happened.
But one of the most bizarre findings that came out of this was how the Liquid Network exploit did not involve a theft of a private key to run this hack. The Liquid $320M hack was actually linked to a vulnerability found in Elements, the open-source software that powers Liquid Network. This development, thus, brought forth a new question in sight. It posed questions related to how such a huge amount of withdrawal was approved when the underlying key was not compromised at all.
Also Read: Fomo Crypto App Explained: Can Social Trading Change How We Trade Onchain?
What Happened to Liquid Network?
Liquid is a Bitcoin sidechain built to support faster and more confidential Bitcoin transactions. The bitcoin locked on the network is represented as LBTC. This allows users to move their BTC between the two networks through the federation-controlled peg mechanism.
On September 6, a transaction involving roughly 4,000 LBTC was sent through SideSwap’s peg-out service. The transaction was approved, which ended up sending approximately 3,996 BTC from Liquid’s Federation reserves to a Bitcoin wallet address held by the attacker. This resulted in the infamous Liquid Network exploit, the scale of which was enormous to take note of.
The withdrawal request sent by the attacker comprised roughly 95% of the Bitcoin held in Liquid’s reported federation reserve. As soon as the attack took place, Liquid Network disabled the bridge nodes. It later asked exchanges to suspend LBTC deposits and withdrawals. This development ended up obstructing the network’s movement between Liquid and Bitcoin while the concerned parties continued to investigate.
The Key Was Not Compromised
A massive Liquid Network exploit like this would have one imagining whether a key was compromised to stage this theft. However, this was not the case. The Liquid $320M hack did not involve factors related to a compromised key.
Liquid and SideSwap shared that their investigation had outlined that a vulnerability in the software powering Liquid Network was exploited. This resulted in the attacker’s request being considered as valid by the software. The concerned parties shared how the withdrawal went through an apparently valid authorization process. SideSwap later added that the LBTC involved in the transaction was created because of a bug found in Elements software.
How Could Invalid BTC Become Real Bitcoin?
The Liquid Network exploit ended up putting a spotlight on the Liquid Network security infrastructure. The investigation further explained how the vulnerability found in Elements allowed LBTC to be created without the corresponding amount of Bitcoin being properly backed by reserves. These tokens then ended up passing through Liquid’s normal peg-out infrastructure.
The standard procedure for Liquid Network is to release the Bitcoin once a request passes through Liquid’s peg-out infrastructure. The STOKR incident report was quick to outline the real cause. It stated how the Liquid Network exploit that resulted in the Liquid $320M hack was due to the fact that it allowed roughly 4,000 LBTC to be created without being backed by real BTC. The report later said that the incident did not involve a compromised peg-out authorization key.
In simple terms, the issue was not that someone stole the key and then used it to withdraw the funds. Instead, the vulnerability appears to have allowed unbacked LBTC to enter a process that ultimately resulted in real Bitcoin being released from the federation’s reserves.
Key Things To Remember
The only thing worth highlighting throughout the Liquid Network exploit is the fact that its infrastructure was exploited, which resulted in Liquid security being compromised. The incident occurred within the infrastructure connecting Liquid’s sidechain representation of Bitcoin to the actual BTC held in the federation reserves.
This development has now become a Bitcoin sidechain infrastructure issue, highlighting a pain point that still needs redressal. Elements is an open-source blockchain platform used to design Bitcoin-linked sidechains. This creates a lesson for the broader crypto community. It highlights how securing private keys is not the only reason through which hacks can be performed. A bug in any crypto infrastructure is lethal enough to shake the foundation of any established platform.
Also Read: Nvidia Hugging Face deal Alters Global Artificial Intelligence Software Development Pipelines
White Hat Attackers Returned the Exploited BTC
The story took an interesting turn when the attackers who performed Liquid Network’s $320M hack returned the stolen BTC. The attackers later described themselves as white hat hackers. They further communicated with Blockstream through on-chain messages. They added how the vulnerability they exploited needed to be fixed first before the funds could be returned.
Once the vulnerability was patched, the attackers returned a large portion of the exploited funds. Nearly 3,400 BTC was returned, while about 598.5 BTC remained outstanding.
However, describing the attackers as white hats should be treated carefully because there has not been a publicly established agreement showing that they were authorized to remove the funds in the first place.
Question About LBTC: How Secure Is It?
The entire Liquid Network exploit centers around LBTC. LBTC on the platform is designed to represent Bitcoin on the Liquid sidechain, with the system intended to maintain a 1:1 relationship with BTC held by the federation. Its usefulness comes from the fact that users can move Bitcoin into the Liquid ecosystem and use its sidechain functionality.
However, this exploit has compelled investors to think hard about whether the system’s safeguards are strong enough to protect that relationship during a software failure.
What To Learn From It?
One of the biggest lessons out of the latest Liquid security hack is to make sure the vulnerabilities in the system are thoroughly checked. It highlights how problems related to crypto infrastructure are still growing and are in dire need of patching assistance. The incident has also put pressure on the wider model used by Bitcoin sidechains. It highlights how crypto hacks can result in various ways, and not just through keys.
This also reflects the growing need to take blockchain/crypto security as a paramount topic for the future to keep the domain safe from further harm. The Liquid Network incident shows that protecting private keys is only one part of security. Transaction validation, software logic, peg mechanisms and reserve management also need to work properly if users are expected to trust a Bitcoin-linked system.
Also Read: Hong Kong Customs Expose Surge in Sanctioned Russian Gold Trade