Bitcoin’s Liquid sidechain, a decentralized network designed to facilitate faster transactions, recently witnessed a significant security incident where actors identifying as white-hat hackers withdrew approximately 4,000 Bitcoin, worth $320 million, from its federation wallet. This withdrawal represents roughly 95% of the wallet’s total balance, prompting Liquid to pause operations as a precautionary measure while the vulnerability is addressed.
Understanding the Liquid Sidechain and Its Vulnerability
The Liquid sidechain, developed by Blockstream, enhances Bitcoin’s capabilities by enabling quicker and private transactions. However, it temporarily halted operations after the incident, disabling bridge nodes to prevent further transactions. According to Blockstream, the withdrawal exploited a bug within Elements, the open-source software that underpins Liquid. The hack has highlighted potential security vulnerabilities within the sidechain’s infrastructure, drawing attention to the need for robust security measures in blockchain technologies.
The White-Hat Hackers’ Demands
The individuals responsible for the withdrawal communicated with Blockstream using signed onchain messages. They demanded that the vulnerability be patched and that all nodes be updated before they would consider returning the funds. This interaction underscores the hackers’ self-proclaimed white-hat status, aiming to expose weaknesses for the greater good. Despite this, as of the latest reports, the funds have not been returned, leaving the situation unresolved.
Impact on the Liquid Network
In the wake of the incident, exchanges have either halted or are preparing to halt L-BTC deposits and withdrawals. This precautionary action is crucial to prevent further exploitation while the vulnerability is addressed. Interestingly, other assets on the Liquid Network, such as USDT, DePix, and certain real-world assets, remain unaffected by this incident. The network’s pause, however, disrupts its normal operations and raises concerns about trust and security among its participants.
SideSwap’s Role and Response
The transaction that led to the massive withdrawal passed through SideSwap’s peg-out service, using its Peg-out Authorization Key (PAK). SideSwap clarified that their systems were not compromised, indicating that the vulnerability lay with the Elements software. The company emphasized that the L-BTC used in the transaction stemmed from a flaw in Elements, not their service, thus redirecting attention back to the core software’s security.
What to Watch Next
As this situation unfolds, several key developments warrant attention:
- Patch Deployment: Monitor Blockstream’s progress in deploying a patch to fix the identified vulnerability. This will be crucial in determining when the Liquid Network can safely resume operations.
- Bitcoin Price Movements: Watch for any impact on Bitcoin’s price, particularly if the withdrawn BTC are moved or sold. This could influence market volatility.
- Return of Funds: Keep an eye on whether the hackers fulfill their promise to return the funds upon the patch’s implementation.
- Regulatory Reactions: Any regulatory scrutiny or guidance following such a high-profile incident could shape future sidechain developments.
Key Takeaways
- Liquid’s operations paused after a $320 million Bitcoin withdrawal by purported white-hat hackers.
- The incident exploited a vulnerability in the Elements software, not SideSwap’s systems.
- 95% of the federation wallet’s Bitcoin was involved in the withdrawal.
- Other assets on Liquid, like USDT and DePix, were unaffected.
- Blockstream is in contact with the hackers to ensure a secure fix and the return of funds.
Risk Disclaimer: Cryptocurrency investments are risky, and past performance is not indicative of future results.





