Attackers claiming white-hat status drained close to 95% of the Liquid Network’s Bitcoin reserves The exploit abused a validation bug in Elements to mint unbacked L-BTC and peg out real Bitco
- Attackers claiming white-hat status drained close to 95% of the Liquid Network’s Bitcoin reserves
- The exploit abused a validation bug in Elements to mint unbacked L-BTC and peg out real Bitcoin
- No private keys were compromised, and every signature on the withdrawal was valid
- Blockstream paused the sidechain and is negotiating a return through messages written into Bitcoin blocks
Blockstream halted its Liquid Network on Sunday after attackers who call themselves white hats withdrew roughly 4,000 BTC, worth about $320 million, from the federation wallet that backs the sidechain’s L-BTC token. The withdrawal cleared through SideSwap, a peg-out partner whose authorization key sits on the federation whitelist, and it emptied close to 95% of the Bitcoin held in reserve. Blockstream disabled the bridge nodes within hours and froze L-BTC deposits and withdrawals. By Monday afternoon the coins had not moved, and both sides were trading conditions for their return in messages written into Bitcoin blocks.
The Elements bug let attackers print L-BTC that no Bitcoin backed
The attackers never stole a key. They found a validation flaw in Elements, the open-source software that runs the sidechain, and used it to mint L-BTC that no Bitcoin backed. That fake L-BTC entered SideSwap’s authorized peg-out service as a routine customer order. The system did exactly what a peg-out is built to do: it burned the incoming L-BTC and released real Bitcoin from the reserve to a fresh address.
Block 965,783 settled the 3,996 BTC withdrawal at 14:28:56 UTC in a single 83-input transaction. The peg wallet started Sunday with about 4,200 BTC and ended with roughly 200. SideSwap says the L-BTC came from the Elements bug, not from any of its systems, and Blockstream confirms no key was compromised.
Bitcoin developer Adam Simecka, founder of MannaBitcoin, framed the timing as the core problem, arguing that Blockstream had been patching an older Elements vulnerability in phases and disclosed where it sat before every node applied the fix. He offered no evidence for intent and called both a serious blunder and a deliberate scapegoat technically plausible. Blockstream has not confirmed how the bug was found or whether the public patching is linked to the drain, and no technical post-mortem has been published.
Eleven functionaries signed a withdrawal the software swore was clean
Liquid’s defenses held right up until they failed. An 11-of-15 multisig guards the peg wallet, so at least eleven of fifteen vetted functionaries must sign any withdrawal, and a second lock, the Peg-out Authorization Key, is meant to stop any single compromised member from moving funds. Both layers worked. Eleven or more hardware modules signed a transaction that, from their side, was entirely valid. Nobody was tricked into approving a bad payment. The software told them the peg-out was backed, and it was not. FailSafe chief executive Aneirin Flynn described the failure as a breakdown in Liquid’s automated validation, one that let a fabricated ledger state walk past the multisig instead of defeating it.
The attackers set their terms in OP_RETURN, and Blockstream answered
The response played out in public, on Bitcoin itself. The attacker address posted an OP_RETURN message claiming white-hat intent and inviting contact on-chain. Blockstream replied in the same channel with a signed message pointing to its security team, a ping that Galaxy Digital’s Alex Thorn logged at block 965,822.
On-chain timeline
●
Sep 6, 14:06 UTC Peg-out request for roughly 3,996 BTC enters through SideSwap’s whitelisted authorization key.
●
Sep 6, 14:29 UTC Federation functionaries sign the withdrawal in Bitcoin block 965,783.
●
Sep 6, afternoon Analyst Ergo BTC flags the drain; Liquid confirms the exploit and pauses bridge nodes.
●
Sep 6, later The attacker embeds an OP_RETURN message claiming white-hat status and asking for contact.
●
Sep 7, block 965,822 Blockstream pings the attacker with 1,000 satoshis and a PGP-signed message.
●
Sep 7, afternoon Funds remain stationary; the attackers condition any return on a patched, fully updated network.
The attackers say they will return most of the funds, but only after Blockstream patches Elements and proves every node runs the fix. “Most” has no number, no deadline, and no name behind it. A return counts only when Bitcoin moves to a federation-controlled address, which had not happened at the time of writing. Blockstream keeps calling the actor a purported white hat, and holding 95% of a network’s backing hostage to force an upgrade sits far from ordinary responsible disclosure.
Circulating L-BTC now trades on five cents of backing
The freeze stops a second withdrawal, but it also strands everyone holding L-BTC.
Frozen Liquid Bitcoin (L-BTC) Deposits and withdrawals suspended. Circulating L-BTC is backed by roughly five cents on the dollar until the funds return. Disrupted Aqua wallet (JAN3) The consumer wallet run by Samson Mow’s JAN3 leans on Liquid rails and is hitting functional outages. Unaffected USDT, DePix, RWAs Stablecoins and tokenized real-world assets issued on the sidechain keep working normally. Unaffected Bitcoin base layer Layer-1 nodes, keys and consensus never came into contact with the exploit.
Containment is the one bright spot. Had the freeze also caught the stablecoins and tokenized assets on Liquid, exchanges would have faced a far wider liquidity event. Bitcoin traded around $79,600 throughout, untouched.
Analysts blame the ledger logic, not the fifteen keys
- Alex Thorn, Head of Research, Galaxy Digital: the case exposes the systemic risk in wrapped and bridged Bitcoin, since a software logic flaw makes the physical distribution of keys irrelevant.
- Aneirin Flynn, CEO, FailSafe (to Bloomberg): preliminary evidence points to a bug that allowed unauthorized minting of L-BTC, and draining roughly 95% of reserves exposes a critical weakness in Liquid’s validation and backing model.
- Discovery method, unconfirmed: several outlets have raised AI-assisted probing as the likely source of the bug, though Blockstream has not said how it was found.
Blockstream’s BitVM bridge suddenly looks less optional
Blockstream now has to find the flaw, ship a patch, and push it to every functionary before repayment is even negotiable on the attackers’ terms. Exchanges have already cut L-BTC deposits and withdrawals, so the token stays illiquid whatever the talks produce. The heavier consequence lands on the federated model itself.
Blockstream had been building a BitVM 1-of-n bridge to reduce reliance on trusted custody, alongside its Simplicity language and quantum-readiness work, and a bug in the legacy Elements system now sits directly in front of that roadmap. Boltz Exchange, a Liquid partner, disabled its swap service weeks earlier and warned that AI-assisted vulnerability probing was outpacing patching. The Liquid drain follows a rough stretch for the sector, with BitMart still working through the fallout of its own breach and Trezor disclosing a customer-data leak that now tops 80,000 people. With crypto protocols already down at least $1.3 billion to hacks through August, verifiable bridges stop reading as a long-term ambition.
The post Liquid Network Exploit Drains $320M, Blockstream Halts Sidechain appeared first on ETHNews.