White-Hat Hackers Exploit Liquid Network for $320M BTC

White-Hat Hackers Exploit Liquid Network for $320M BTC

A group claiming to be white-hat hackers withdrew $320 million in bitcoin from Liquid Network over the weekend, exploiting a flaw that let them manufacture unbacked tokens and swap them for genuine BTC. The actors have since returned 85 per cent of the haul after Blockstream, Liquid's developer, patched the vulnerability. As of Tuesday roughly 600 BTC—worth approximately $47 million—remained in the actors' hands, and neither party has publicly confirmed whether those funds constitute a bounty or will be returned.

  • Self-described white-hat actors drained roughly 4,000 of the 4,200 BTC held in Liquid Network's reserve by minting L-BTC tokens that had no corresponding bitcoin backing.
  • The exploit turned on a caching flaw in Liquid's transaction-validation software, which allowed invalid data to pass verification by pointing to a previously approved result.
  • Following on-chain negotiations with Blockstream, the actors sent back 3,400 BTC in a single transaction once the developer confirmed its bridge nodes had been updated and secured.

Liquid Network operates as a sidechain to Bitcoin, designed to offer faster settlement, lower fees and confidential transactions for bitcoin-based finance. Users peg in BTC and receive L-BTC—tokens that under normal operation are fully backed one-to-one by real bitcoin held in the network's reserve. On Sunday that backing mechanism broke when the actors managed to create L-BTC without first depositing any BTC, then used those unbacked tokens to withdraw genuine bitcoin through Liquid's peg-out process.

The hackers contacted Blockstream shortly after the drain, identifying themselves as whitehats and offering to return the majority of the stolen funds once Blockstream had fixed the bug that made the theft possible. By Wednesday Blockstream had deployed patched software and Liquid Network had recovered 85 per cent of what was taken. Discussions with the purported whitehats continued as of Tuesday regarding the return of the remaining balance.

The incident underscores that additional layers built on top of secure blockchains can introduce their own points of failure. Bitcoin itself remained uncompromised throughout; the weakness lay in the mechanism Liquid used to mint and redeem its pegged tokens.

Flaw in transaction validation

The vulnerability allowed the actors to trick Liquid into accepting L-BTC that was never backed by actual bitcoin deposits. Once Liquid's software treated those tokens as legitimate, the actors exchanged them for real BTC held in the network's reserve and withdrew the funds onto the Bitcoin blockchain.

An analogy: imagine a bank's online platform contains a bug that lets someone artificially inflate their account balance without making a deposit, then withdraw that phantom balance as cash. In Liquid's case the actors inflated their L-BTC holdings without locking up the corresponding BTC, then withdrew roughly 4,000 real bitcoin through the network's standard redemption process.

The root cause lies in how Liquid verifies transactions. Because Liquid uses Confidential Transactions—a privacy feature that hides transaction amounts—the network relies on cryptographic proofs to confirm that users are not creating value from nothing. One such proof, called a range proof, prevents the minting of unbacked assets.

Verifying these proofs is computationally expensive, so Liquid's software caches successful verification results to avoid redundant checks on identical data. The flaw resided in the system used to identify cached results: new data could be mistakenly matched to a cached approval even when the new data differed from what had originally been verified.

The actors exploited this by submitting valid data that passed verification and was cached, then submitting different, invalid data that the system incorrectly linked to the same cached result. Affected nodes treated the invalid data as already verified rather than checking it afresh. This allowed the actors to mint L-BTC without the required bitcoin backing and exchange those tokens for real BTC held in Liquid's reserve.

Messages embedded in Bitcoin transactions

After draining the reserve, the purported whitehat hackers communicated with Blockstream by embedding messages in Bitcoin transactions using the OP_RETURN field. Some of the exchanges were written in plaintext; others were encrypted.

In an early plaintext message the actors stated they would return the bitcoin once Blockstream had repaired the vulnerability that enabled the theft. "The chain is under risk at latest commit," one message read, followed by the instruction: "make sure every node is patched."

Blockstream confirmed on-chain that its bridge nodes had been patched and that returning the funds would not expose them to further risk. The actors then sent 3,400 BTC—roughly 85 per cent of the total withdrawn—back to Liquid in a single transaction. The same transaction routed the remaining 600 BTC as change to an address controlled by the actors.

As of Tuesday that 600 BTC, valued at approximately $47 million, had not been returned. The reason for the retention is unclear. Some observers have suggested the sum could function as a de facto bounty, but neither Blockstream nor the actors has publicly confirmed any such arrangement.

Blockstream has since announced that it deployed updated software and is preparing Liquid Network for a restart.

Purported white-hat hackers exploited a flaw in Liquid's transaction-validation software that let them create thousands of unbacked L-BTC tokens. They then withdrew roughly 4,000 real BTC from Liquid's reserves, worth around $320 million at the time. L-BTC, or Liquid Bitcoin, is a token used on Liquid Network that under normal circumstances is backed one-to-one by BTC held by the Liquid Federation. Users move between Bitcoin and Liquid through a peg-in and peg-out process. The vulnerability involved the way Liquid's software cached cryptographic verification results. The attackers made invalid transaction data point to a previously approved cached result, allowing the data to bypass a full verification check and enabling L-BTC to be minted without corresponding BTC backing it. Roughly 4,000 of the approximately 4,200 BTC held in Liquid's reserve was withdrawn onto the Bitcoin blockchain, worth around $320 million at the time. Following an exchange of messages with Blockstream through Bitcoin transactions, the actors returned 3,400 BTC to Liquid. Roughly 600 BTC, worth around $47 million as of Tuesday, remained under their control, and neither Blockstream nor the actors has publicly confirmed what will happen to those remaining funds. The incident illustrates the distinction between the security of an underlying blockchain and the infrastructure built around it. As institutions increasingly rely on sidechains, bridges, wallets, exchanges, custodians and settlement providers, assessing the resilience of those additional layers is an important part of managing digital-asset risk.

Source: www.chainalysis.com

Free First Assessment

Let's recover your funds.

  • Free case analysis — no commitment
  • Analyst reply in under 10 min
  • NDA by default

Your contact details *