TLDR
- Liquid Network has restarted block production while maintaining a suspension on transactions and peg-out operations
- Self-identified white-hat hackers extracted approximately 4,000 Bitcoin valued at $320 million from the network
- The attackers returned 3,400 BTC (approximately $270 million) following confirmation of node security patches
- Approximately 598 BTC valued at roughly $46 million has not been returned with no clear timeline for recovery
- A critical software patch, Elements v23.3.4, was deployed to address the proof-verification cache vulnerability
The Liquid Network has reactivated block production on its Bitcoin sidechain infrastructure, though transaction processing and peg-out mechanisms remain disabled after a massive $320 million Bitcoin extraction that revealed a critical vulnerability in the network’s underlying codebase.
What Happened
On September 6, individuals identifying themselves as ethical security researchers extracted approximately 4,000 Bitcoin from the Liquid federation’s custodial wallet. This withdrawal accounted for nearly 95% of the entire wallet holdings at that moment.
The extraction exploited a vulnerability within Elements, the open-source codebase underlying the Liquid sidechain. The security flaw resided in the proof-verification cache mechanism, a component designed to store validated confidential transaction proof results to optimize node performance by avoiding redundant verification operations.
This vulnerability allowed previously validated proof results to be inappropriately reused in scenarios where verification should have failed. The exploiter leveraged this weakness to mint L-BTC, Liquid’s Bitcoin-pegged asset, without depositing the corresponding amount of actual Bitcoin into the federation’s reserve wallet.
The attacker subsequently submitted these unbacked L-BTC tokens through SideSwap’s authorized withdrawal mechanism. The system processed this request as legitimate, triggering the federation to release approximately 3,996 actual Bitcoin, depleting the wallet from roughly 4,205 BTC down to approximately 202 BTC.
Importantly, no federation cryptographic signing keys were compromised. The vulnerability existed exclusively within the software logic responsible for validating the legitimacy of L-BTC tokens presented for redemption.
Recovery Progress
Communication between Blockstream and the attackers occurred through on-chain messages encoded within Bitcoin transaction data. The actors indicated they would repatriate the extracted funds once security patches were implemented across network nodes.
Following Blockstream’s verification that its bridge infrastructure had been successfully patched, the attackers returned 3,400 BTC, representing approximately $270 million in value. This repatriation restored roughly 85% of the initially withdrawn assets.
Approximately 598 BTC, currently valued at around $46 million, continues to remain in addresses associated with the original withdrawal. No public agreement has been disclosed confirming whether this represents an authorized security bounty or establishing any timeline for its potential return.
Charles Guillemet, Chief Technology Officer at Ledger, publicly challenged the white-hat characterization of the actors. He argued that retaining approximately 600 BTC without transparent terms resembles extortion rather than conventional responsible disclosure practices and security bounty arrangements.
Software Fix and Current Status
Liquid deployed an emergency software update, Elements v23.3.4, approximately one day prior to resuming block production. This patch modifies the cache key storage methodology used during range proof validation, effectively eliminating the vulnerability the attacker exploited.
Functionary nodes and bridge infrastructure received the security update before block signing operations were reactivated. The Liquid federation operates through 15 rotating functionary operators and requires 11 cryptographic signatures to authorize fund movements.
Block production has resumed but operates in a restricted mode without transaction processing capabilities. Liquid indicated that maintaining this suspension on transfers allows the team to verify deployment stability before reactivating additional network services.
Peg-out operations, including PAK-authorized withdrawals, continue to remain offline. Liquid has not communicated a specific timeline for restoring transaction capabilities or bridge functionalities.
L-BTC token holders are presently unable to redeem their holdings for native Bitcoin through standard procedures. No United States regulatory authority has publicly announced any investigative actions or enforcement measures related to this security incident.
The post Liquid Network Hackers Return $270M After $320M Bitcoin Exploit, Keep $46M appeared first on Blockonomi.
