Pull to refresh
Logo
Liquid Network drained of 4,000 BTC in Elements bug exploit

Liquid Network drained of 4,000 BTC in Elements bug exploit

Money Moves

Purported white-hat hackers say they'll return most funds once the bug is patched

Yesterday: SideSwap processes 4,000 L-BTC peg-out

Overview

Updated 1 hour ago

Liquid, a Bitcoin sidechain run by Blockstream, lost nearly all its bitcoin reserves on September 6. A single peg-out transaction moved about 4,000 BTC, worth roughly $320 million, out of the federation wallet onto the Bitcoin mainchain. The wallet held about 4,200 BTC before the transfer; it now holds roughly 200.

The withdrawal wasn't a key theft. Someone exploited a validation bug in Elements, the open-source software that powers Liquid, to create L-BTC that no real Bitcoin backed, then redeemed it through a legitimate-looking peg-out. Liquid says no federation key was compromised.

Liquid paused its bridge nodes and asked exchanges to suspend L-BTC deposits and withdrawals. The party behind the withdrawal says it's white-hat hackers who will return most of the funds once the bug is fixed on every node. Blockstream replied, 'Yes, thank you.'

Why it matters

If the bitcoin isn't returned, L-BTC holders are stuck with tokens backed by a wallet that's 95% empty.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

~4,000 BTC
Bitcoin withdrawn from the federation wallet
Worth roughly $320 million at the time of withdrawal.
95%
Share of federation reserves withdrawn
The wallet dropped from about 4,200 BTC to roughly 200 BTC.
5 weeks
How long the Elements fix was available before the exploit
Blockstream added the fix five weeks before the withdrawal, but not all nodes were patched.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 3 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

7 events Latest: Yesterday
Tap a bar to jump to that date
  1. SideSwap processes 4,000 L-BTC peg-out

    Latest Security Incident

    A customer's 4,000 L-BTC is burned under a valid authorization at SideSwap's bridge service.

  2. Block 965,783 settles 3,996 BTC payout

    Security Incident

    The federation releases 3,996 BTC from the reserve wallet in one 83-input transaction.

  3. Liquid disables bridge nodes, alerts exchanges

    Statement

    Liquid announces the withdrawal, pauses bridge nodes, and asks exchanges to suspend L-BTC.

  4. Hackers identify themselves on-chain

    Communication

    The destination address broadcasts 'we are whitehats. contact us on chain' via OP_RETURN.

  5. Blockstream responds, negotiations go on-chain

    Communication

    Blockstream shares its security team's email; PGP-signed messages are exchanged in Bitcoin transactions.

  6. Hackers set return conditions

    Communication

    Hackers say they'll send back most funds after the Elements bug is fixed on every node.

  7. Blockstream replies 'Yes, thank you'

    Communication

    Blockstream confirms the deal; roughly 3,998.5 BTC remains at the hackers' address.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

June 2016

The DAO hack (2016)

An attacker drained about $60 million from The DAO, a smart contract on Ethereum, using a reentrancy bug. The attacker argued the code permitted the withdrawal, calling it a legitimate exercise of the contract's rules.

Then

The Ethereum community hard-forked the blockchain to reverse the theft, splitting the network into Ethereum and Ethereum Classic.

Now

The incident set a precedent that code exploits could be reversed through community consensus, and it framed the debate around whether an exploit that follows the code's letter is theft.

Why this matters now

Like the DAO, this Liquid exploit used a legitimate-looking transaction that exploited a code bug. The white-hat justification echoes the DAO attacker's argument, though this party is offering to return the funds.

March 2022

Ronin Bridge hack (2022)

Attackers stole $625 million from the Ronin bridge, which moved funds between the Axie Infinity game and Ethereum. Compromised private keys, not a code bug, allowed the drain, making it the largest DeFi hack at the time.

Then

US law enforcement recovered about $30 million and later indicted two individuals. The Securities and Exchange Commission charged the parent company, Sky Mavis.

Now

The case showed both the vulnerability of bridges and sidechains and the reach of law enforcement in recovering stolen crypto.

Why this matters now

Ronin was a sidechain bridge exploit on a massive scale, like Liquid. Its recovery came through law enforcement action rather than negotiation, offering a contrasting path to resolution.

February 2022

Wormhole bridge hack (2022)

A hacker drained $320 million, roughly the same amount as this Liquid incident, from the Wormhole bridge using a signature validation bug. Jump Crypto, which backed the project, replaced the funds within hours.

Then

Wormhole users were made whole. The attacker remained unidentified but later returned $155 million.

Now

The incident showed that a financial backer could absorb losses to protect user confidence, and that crooks sometimes return a portion of stolen funds.

Why this matters now

Wormhole's $320 million loss matches this exploit almost exactly. It illustrates the scale of bridge and sidechain hacks and one path to resolution: a deep-pocketed backer covering the loss.

Sources

(8)