Liquid Network Restores Operations After $320M Bitcoin Sidechain Exploit
The Liquid Network, a Bitcoin sidechain operated by Blockstream, has resumed block production after a security incident in which attackers extracted around 4,000 Bitcoin, nearly 95% of the funds held in its custodial wallet. The individuals involved identified themselves as ethical security researchers.
The root cause was a flaw in Elements, the open-source software underlying Liquid, specifically in a caching component meant to speed up verification of confidential transactions. This flaw let previously validated results be reused incorrectly, allowing the attacker to mint Liquid's Bitcoin-pegged token (L-BTC) without actually depositing real Bitcoin. They then redeemed these fake tokens through a legitimate withdrawal service, tricking the network into releasing genuine Bitcoin. No cryptographic signing keys were stolen; the issue was purely in the software logic validating token redemptions.
The attackers communicated with Blockstream via messages embedded in Bitcoin transactions and indicated they would return the funds once the vulnerability was patched. According to reports, around $270 million has since been returned, with $46 million reportedly retained. Transaction processing and withdrawal features remain disabled while recovery continues.