The Liquid Network Hack Began as a Fix for a 2019 Bug

The Liquid Network hack drained about 4,000 bitcoin, yet no keys were stolen. A patch meant to fix a 2019 flaw let the attacker mint unbacked coins.

Jan Whitfield News

The Liquid Network hack that emptied a federation wallet over the weekend carries a detail most of the coverage skipped. No private key was stolen. The roughly 4,000 bitcoin that walked out the door, worth about $320 million, were pegged out with a signing key that behaved exactly as designed. What broke sat one layer below the keys, in the ledger that is supposed to keep bitcoin scarce.

Blockstream, which launched Liquid in 2018 as a bitcoin sidechain run by a federation of more than 80 firms, disclosed the incident on Sunday and paused the network. About 4,000 of the roughly 4,200 bitcoin backing the chain were gone, close to 95 percent of the peg wallet in a single sweep.

The attacker minted bitcoin the network could not tell apart

Liquid works by locking real bitcoin and issuing a matching token, Liquid Bitcoin, one for one. The exploit let the attacker create Liquid Bitcoin that had nothing locked behind it. Roughly 4,000 unbacked tokens, indistinguishable to the software checking them. The attacker then used SideSwap's peg-out authorization key to turn those tokens back into ordinary bitcoin and move it off the chain.

Nodes that were already patched rejected the fraudulent transactions and simply stopped, stalling at block height 4,050,335. The unpatched ones waved the coins through. It is the same shape as the bridge exploit that minted a billion phantom tokens earlier this year, only this time the phantom asset was pegged bitcoin.

A 2019 fix opened the door

The bug did not come from neglect. It arrived inside a recent patch that was trying to close an older cryptographic proof-validation flaw dating to 2019. The repair gave the node software a new way to accept invalid coin creation. Fixing one thing broke another, and the second break was worse.

Researchers have started pointing at the peg-out step too. Liquid's rules say members should only peg out to an offline cold wallet, and if SideSwap let funds move anywhere else, part of the blame lands there. The same seam keeps showing up, where one relaxed control turns a bug into a drain. Price and access manipulation already sat behind one in eight crypto hacks this year.

Most of the money came back within a day

By Monday the attacker had returned 3,400 bitcoin, around $263 million, and framed it as a white-hat rescue. The message to the federation asked them to patch every node first, then the money would come back safely. About 598 bitcoin, near $47 million, has not returned. Prosecutors tend to read a demand attached to stolen funds as extortion, not charity, whatever the sender calls it.

Networks have clawed value back before, from Arbitrum reaching into a hacker's wallet to freeze $71 million to Litecoin rewriting three hours of its own chain to undo an exploit. What sets the Liquid Network hack apart is that its recovery rests less on code than on the goodwill of the person who took the coins.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.