Hackers stole about $320 million worth of bitcoin from the Liquid Network over the weekend, a blockchain platform launched in 2018 by Blockstream Inc. The attackers returned most of the stolen funds earlier today, retaining 598 of the 4,000 coins for a total of approximately $47 million. In a message to Blockstream embedded in a public Bitcoin transaction log, the hackers stated they would keep the remaining funds as a “bounty” for drawing attention to a vulnerability in the network’s infrastructure.
The mechanics of the theft
The theft occurred through SideSwap, a system used to move funds between blockchains. Users deposit bitcoins into SideSwap, which moves them to a virtual vault and issues platform-specific stablecoins with equal value. When users wish to exit the network, the system returns their original bitcoin deposits. The attackers exploited a flaw in Elements, an open-source project that powers the Liquid Network’s centralized transaction approval workflow.
This process relies on a piece of data called the peg-out authorization key, or PKA. The Liquid Network’s maintainers claim the hackers used the PKA to access the funds, though they assert that the key itself was “not compromised.” The 4,000 coins stolen represented about 95% of the Liquid Network’s Bitcoin reserve, though other cryptocurrencies stored on the sidechain remained unaffected. The specific mechanism of the Elements project facilitated this centralized workflow, allowing the vulnerability to be exploited despite the security claims regarding the PKA.
A centralized approach to verification
The Liquid Network functions as a layer two Bitcoin network, or sidechain, built on the infrastructure that powers Bitcoin. While Bitcoin processes transactions through a decentralized process where thousands of user-operated servers verify authenticity, the Liquid Network replaces this with a more centralized workflow. In this model, the task of verifying payments is performed by a group of about 80 organizations, including cryptocurrency wallet providers and exchange operators. At any given time, only about 15 of these entities play an active role in the verification process.
Unlike Bitcoin, where users can view the value of one another’s transactions, the Liquid Network maintains a different standard for transparency. The centralized nature of this verification process presents a structural difference from the underlying Bitcoin protocol. This difference in operational structure is what allowed the breach to occur through the Elements open-source project, which facilitates the specific workflow used by SideSwap. The reliance on a smaller group of active verifiers creates a single point of failure that is absent in the Bitcoin network’s distributed architecture.
The hackers involved in this incident appear to have treated the theft as a form of coordinated disclosure. By returning the vast majority of the funds, they ensured that the platform could continue operating while retaining a portion of the assets as a reward for identifying the weakness. This approach creates a tension between the principles of cryptocurrency security and the reality of centralized infrastructure management. While the attackers’ actions resulted in a significant financial impact, the swift return of the majority of funds suggests a calculated effort to demonstrate the flaw without destroying the platform entirely. The remaining 598 bitcoin now sit in the attackers’ possession, held as a bounty for the discovered vulnerability.
