Liquid Network loses $320M in crypto hack

Sudhanshu Ranjan
Written by Sudhanshu Ranjan

Liquid Network, a blockchain network tied to Bitcoin and used by several cryptocurrency exchanges has suffered a $320 million hack, marking the latest major breach to rattle confidence in digital-asset security. Attackers stole about 4,000 Bitcoin, worth roughly $320 million, from its federation wallet. The amount represented about 95 per cent of the approximately 4,200 BTC held in the wallet.

While users looked into the situation, the network stopped accepting new transactions. The actors in question were referred to by Liquid as “purported white-hat hackers.” Although the technical source of the event has not been verified, blockchain analysis has shown a potential L-BTC inflation vulnerability.

In a post on X (formerly twitter), the company described the perpetrators as “purported white-hat hackers” who claim to exploit vulnerabilities with the intention of returning the funds, typically in exchange for a fee.

Attack drained about 95% of reserves

The reported reserve loss is noteworthy because Liquid relies on one-to-one backing between L-BTC and BTC held by the federation. L-BTC is intended to be backed 1:1 by Bitcoin stored on the Bitcoin mainchain, according to Blockstream’s documentation. The federation wallet had about 4,200 BTC prior to the occurrence, so the withdrawal of nearly 4,000 BTC eliminated the majority of the reserve.

According to recent reports, the issue might be more complicated than a total loss of support. The amount of L-BTC burned about equaled the amount of BTC issued, according to some on-chain study. If so, rather than a situation where all remaining tokens abruptly become unbacked, the fundamental problem might be the unlawful creation or validity of a transaction.

The people behind the theft are referred to as white-hat hackers, whose definition normally applies to the exploits of security researchers who exploit vulnerabilities with an aim of securing a system, not for financial gains. It is alleged that their on-chain message asked Liquid’s developers to patch up the hole before returning the Bitcoins. The on-chain message has been explained as an effort at communicating directly through the blockchain.

Understanding Liquid Network

Liquid is a sidechain of the Bitcoin blockchain aimed at facilitating fast and private transactions for exchanges, institutions, traders and other firms in the crypto assets industry. This is according to information from Blockstream, which indicates that its transactions take one minute as opposed to those on Bitcoin.

Blockstream says the Liquid Federation comprises more than 80 Bitcoin-focused companies. At the same time, a smaller group of specialised functionaries is responsible for generating blocks and safeguarding the Bitcoin reserves that support the network.

L-BTC, or liquid Bitcoin, is at the centre of the system. An identical quantity of L-BTC is issued on Liquid when users deposit Bitcoin into a federation-controlled wallet on the main blockchain. In order to redeem Bitcoin, the same amount of BTC is released from the federation wallet and the corresponding L-BTC is destroyed (or burned).

The process of turning L-BTC back into Bitcoin on the main blockchain is called a peg-out. Only federation members may directly submit a peg-out request in accordance with Liquid’s regulations. The comparable quantity of L-BTC must be burnt before any Bitcoin is released.

Inside SideSwap link

According to Liquid, SideSwap, a settlement platform allowed to handle network transfers, was used to remove the impacted funds. Additionally, the business claimed that the pertinent authorisation key had not been compromised. Instead of focusing on a straightforward theft of private keys, that detail highlights the software and transaction validation procedure. Liquid’s claim that the encryption key used in the transactions had not been compromised was reported separately by Reuters.

Based on the information available so far, there is no indication that attackers stole the federation’s private keys. Liquid said the key used in the SideSwap-related withdrawal was not compromised. That is significant because the network relies on multiple functionaries, hardware security modules, and an 11-of-15 multisignature setup.

Researchers in security have identified a possible security flaw in the Elements/Liquid software and an L-BTC inflation flaw. According to Bitquery, about 4,000 L-BTC could have been minted “out of nowhere” to exploit the peg out mechanism. The investigation is currently on, and it is essential to differentiate between blockchain analysis and a forensic explanation.

Recent crypto hack trends

The Liquid incident comes amid a series of security problems across the crypto sector. It follows a reported $6 million loss from a Crypto.com-linked digital-asset lending platform and a major attack involving Coldcard hardware wallets in August.

Hardware wallets are generally regarded as one of the safer ways to store Bitcoin, which is why the Coldcard event attracted attention. Researchers discovered flaws in some Coldcard firmware versions in August that would enable hackers to recreate susceptible wallet seeds without having physical access to the devices. Earlier blockchain investigation revealed thousands of impacted addresses, and CoinDesk reported losses of up to $114 million.