- A group claiming to be white-hat hackers withdrew $320 million in BTC from Liquid Network's reserve by exploiting a transaction-validation flaw.
- The vulnerability let the actors mint L-BTC tokens without depositing backing bitcoin, then exchange those tokens for real BTC held in the network.
- The group returned 3,400 BTC after Blockstream patched the software; roughly 600 BTC worth $47 million stayed in their control.
Over the weekend, individuals identifying themselves as white-hat hackers exploited Liquid Network and withdrew $320 million in bitcoin that should have remained locked. They drained approximately 4,000 of the 4,200 BTC held on Liquid Network, a Bitcoin sidechain designed for faster, lower-cost transactions. L-BTC tokens on Liquid normally represent deposited bitcoin on a one-to-one basis.
The exploit broke that peg. The actors minted L-BTC without first depositing the corresponding BTC, then traded those unbacked tokens for real bitcoin other users had placed in Liquid. After moving the BTC out, they contacted Blockstream—the network's developer—calling themselves whitehats and offering to return most of the withdrawn funds once Blockstream fixed the bug.
By Wednesday, Blockstream had deployed patched software and Liquid Network had received back 85% of what was taken. The remaining $47 million stayed with the actors. On Tuesday, Liquid Network stated that discussions with the purported whitehats continue regarding the return of the outstanding funds.
The episode exposed a flaw in the mechanisms Liquid uses to mint and redeem L-BTC, even though Bitcoin itself remained secure throughout.
Software flaw in transaction validation
The vulnerability allowed the actors to fool Liquid into accepting L-BTC that lacked bitcoin backing. Once accepted, they converted that unbacked L-BTC into actual BTC from the network's reserve.
The flaw resided in how Liquid verified transactions. Liquid relies on Confidential Transactions, which conceal transaction amounts and require cryptographic proofs to confirm validity. Range proofs are among these checks, preventing users from conjuring assets from nothing.
Verifying proofs demands computing resources, so Liquid's software cached successful verification results to avoid redundant checks on identical data. A flaw in the system identifying those cached results meant new data could be mistaken for previously approved data.
The actors exploited this by first submitting valid data that passed verification and was cached. They then submitted different, invalid data that referenced the same cached result. Affected nodes treated the new data as already verified rather than checking it again. This allowed the actors to create unbacked L-BTC and swap it for real bitcoin.
On-chain messages between actors and Blockstream
The actors used Bitcoin's OP_RETURN field to communicate with Blockstream in the hours following the exploit. Their on-chain messages mixed plaintext and encrypted content.
In an early plaintext message, the actors said they would return the BTC once Blockstream had fixed the vulnerability that enabled the theft. They wrote that the chain remained at risk at the latest commit and instructed Blockstream to ensure every node was patched.
Once Blockstream confirmed on-chain that its bridge nodes had been patched and the funds could be safely returned, the actors sent back 3,400 BTC—approximately 85% of the withdrawn amount—in a single transaction. The same transaction returned the remaining roughly 600 BTC as change to an address the actors controlled.
As of Tuesday, that 600 BTC, worth roughly $47 million, remained under the actors' control. It is unclear why those funds have not been returned. Some observers have speculated the remaining funds could constitute a bounty, but neither Blockstream nor the actors has publicly confirmed any such arrangement.
Blockstream has since announced it deployed updated software and is preparing the network for a restart.
Hot Stories
- Investigations Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit
- Investigations Blockstream rejects ransom demand after $320M Liquid hack
- Investigations OFAC and DOJ Freeze $52M in Xinbi Crypto Laundering Network
- Investigations OFAC sanctions Shelbit and affiliates for $6.3B crypto flows
- Investigations Cronos halts blockchain after $75M Tectonic DeFi exploit
- Investigations EigenWallet and BTC–XMR Atomic Swaps: How Stolen Crypto Is Obscured
- Investigations More Markets loses $9.3M in Wrapped Flow exploit on Flow EVM
- Investigations Can Stolen Crypto Be Recovered? What Changes the Odds
- Investigations A Predictable COLDCARD Seed Put $130M in Bitcoin at Risk
- Articles A legitimate user can get their USDT frozen over funds with a tainted history.
