Viet Reader.

VR.

Premier Newspaper for Vietnamese Worldwide

Liquid Network Suffers $320 Million Attack Linked to Bitcoin

Liquid Network Suffers $320 Million Attack Linked to Bitcoin

The Liquid Network, a sidechain linked to Bitcoin that is utilized by various international exchanges, has recently experienced a significant security breach. Approximately 4,000 Bitcoin, equivalent to $320 million, was withdrawn from the network's reserve wallets. This alarming incident has led to the suspension of all new transactions on the network, raising concerns about the safety of the technology underpinning Bitcoin.

Security Breach Details

The Liquid Network confirmed that the attackers managed to withdraw around 4,000 out of a total of 4,200 Bitcoin stored in the Liquid Federation's wallets, resulting in a loss of approximately $320 million. Representatives from the network stated that the perpetrators claimed to be "white hat hackers," suggesting they exploited vulnerabilities to alert the network and intended to return the funds after receiving a bounty.

In response to the breach, the Liquid Network has temporarily halted all new transactions and warned users that Liquid wallets may be affected. Members of the managing federation are collaborating to address the issue and restore normal operations as soon as possible.

Understanding the Liquid Network

The Liquid Network operates as a sidechain, meaning it runs parallel to the main Bitcoin network and is directly linked to it. Due to frequent congestion on the Bitcoin mainchain, which leads to slower transaction times and higher fees, the Liquid Network was designed to expedite payments by issuing Liquid Bitcoin (L-BTC) based on the amount of Bitcoin locked as collateral.

This project was launched by Blockstream in 2018, co-founded by cryptography expert Adam Back. Currently, the Liquid Network is managed by a federation comprising over 80 exchanges, infrastructure companies, and large asset management organizations, such as BTSE, Bitfinex, and BitMEX.

Implications of the Attack

This attack occurs amid ongoing cybersecurity challenges facing the cryptocurrency sector. Just last week, a lending platform associated with Crypto.com lost $6 million, and an attack on the Coldcard offline wallet in August sparked debates over the safest methods for storing digital assets.

Experts have noted that the incident, which saw nearly 95% of the Bitcoin reserves drained, highlights serious vulnerabilities in the centralized storage model of the Liquid federation. Despite the attackers identifying as white hat hackers, the substantial amount of stolen assets remains outside the control of the project, with no guarantees on when or how much Bitcoin will be returned.

Root Cause of the Breach

Initial investigations revealed that the funds were withdrawn through the SideSwap payment platform, which is authorized to process asset conversion transactions from the Liquid Network. SideSwap representatives asserted that their decentralized payment keys were not exposed or compromised during the withdrawal process.

Aneirin Flynn, CEO of cybersecurity firm FailSafe, indicated that preliminary evidence points to a technical flaw in the system that allowed the creation of new L-BTC tokens without the need for actual collateral deposits. This incident has exposed a critical weakness in the validation and collateralization model of the Liquid Network, as nearly all reserves were drained.

Blockstream later confirmed that the L-BTC used in the withdrawal command was created due to a bug in the Elements software, the open-source platform used to operate the Liquid Network. This flaw prevented the payment system from distinguishing between valid and counterfeit tokens, leading to the release of real Bitcoin from the reserve fund.

Independent analyst DBCrypto noted that the withdrawn Bitcoin remains in a single address on the Bitcoin network and has not been funneled through mixing services to obscure its trail. This behavior aligns more with a security testing withdrawal rather than an outright theft for asset liquidation.

Nevertheless, analysts stress that this incident raises significant questions about the safety of this sidechain, as the transaction control list failed to prevent unusual withdrawal commands. Samson Mow, CEO of Jan3, shared on social media that technical teams are working diligently to resolve the issue and are committed to helping the community navigate this challenging period.

About author
You should write because you love the shape of stories and sentences and the creation of different words on a page.
View all posts
More on this story