The Liquid a Network breach allowed the unauthorized exit of 3,996 bitcoins, valued at nearly $320 million. Since then, the perpetrators have already returned 3400 BTC, however the exact technical origin and fate of the remaining 598.5 BTC still remain unknown.

In brief
- 3996 BTC left Liquid Network in an unauthorized transaction.
- The multisignature has not been compromised, the possibility of a software flaw is favored.
- The analyzes notably examine the PAK control and the Zero-Knowledge Proofs verification cache.
- The authors, who present themselves as white hats, returned 3400 BTC.
- Around 598.5 BTC remains unreturned, while the exact technical cause remains unknown.
Liquid’s multisignature hasn’t been broken
Liquid functions as a sidechain of Bitcoin. Users deposit bitcoins to receive L-BTC. Then, they make a withdrawal via conversion to get their funds back on the main blockchain.
On September 6, a transaction led to the withdrawal of nearly 3,996 BTC. The Liquid federated network signed the transaction because the system interpreted it as a valid conversion withdrawal. However, Blockstream ensures that the cryptographic keys of the multisignature and those used to authorize withdrawals have not been compromised.
Four facts allow us to measure the scale of this incident:
- Nearly 3996 BTC were released during the main operation;
- The transaction appears in Bitcoin block 965783;
- The federated wallet went from around 4205 to 203 BTC;
- Bitcoin’s main blockchain has not suffered any compromise.
The flaw linked to Liquid Network is therefore located in the software which verifies the legitimacy of operations. The keys of the eleven signatories were not stolen, because they were not forced. So they authorized a request that the system presented to them as valid.
The funds are passed through SideSwap, a service authorized to make withdrawals by conversion. SideSwap then indicated that the L-BTC used came from a bug in Elements, open source software on which Liquid is based, and not from its own systems.
PAK control constitutes a first hypothesis
The security report sent identifies the PAK mechanism as an area for review. It is a system that links each conversion withdrawal to an authorized destination through cryptographic proof. Any request to an address not on the white list should normally be rejected.
Careful analysis of the code reveals that this check appears under various conditions. This report then considers the existence of a branch where control could not apply. An unauthorized transaction could be considered valid before reaching the signers.
However, this explanation remains a hypothesis. The document indicates that the phases regarding the bypass of PAK control are not confirmed. Blockstream has therefore not published the exact cause or the method used.
A separate Bitquery investigation points to the cache for verifying zero-knowledge proofs (Zero-Knowledge Proof). The address concerned would have carried out the registration of identical proof 68 times before the creation of the L-BTC used for the withdrawal. A correction relating to this cache had been added to the code before the incident, however it was not included in the latest public version.
It is not yet possible to definitively identify the fault using the two analyses. However, they reveal that hackers certainly did not break multisignature. They would have deceived a software layer located upstream.
The authors still keep around 598.5 bitcoins
After their forfeit, a message was inserted by those responsible into a Bitcoin transaction. They therefore declare in the OP_RETURN field:
We are white hats. Contact us on the blockchain.
Then, Blockstream provided a response through messages signed with its PGP key. The authors therefore requested that each node be fixed before funds were returned. Ultimately, the company clarified that the bridge nodes had received a fix and that it was safe for return of funds.
This September 7, a transaction verified on the blockchain transferred 3400 BTC to the federated wallet. Nearly 598.5 BTC was returned to another address controlled by the perpetrators, or around $48 million at the current price.
There is no public evidence that the 598.5 BTC constitutes a negotiated premium. Until Blockstream indicates their status, they should be considered unreturned. The blockchain also remained suspended at the time of the last checks, without a new public version of Elements containing the fix.
The next step will be to publish the technical cause, audit the correction and restore full coverage of L-BTC. Without these guarantees, the return of a majority of the funds is not sufficient to close the incident.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
