Crime

How The $320M Exploit of Liquid Network Went Down

Summary

  • Purported white-hat hackers exploited the Liquid Network to withdraw $320 million in BTC from the network’s reserve.
  • A vulnerability in Liquid’s transaction-validation software allowed the hackers to create unbacked L-BTC tokens and exchange them for real BTC.
  • Ae actors returned 85% of the withdrawn BTC, while Blockstream deployed updated software to address the vulnerability.

Over the weekend, a group of purported white-hat hackers exploited Liquid Network with a heist that should not have been possible: they withdrew $320 million in real bitcoin (BTC) — essentially for free.

The hackers drained roughly 4,000 of the 4,200 BTC held on Liquid Network, a sidechain to Bitcoin that, under normal conditions, acts as a high-speed, low cost, confidential highway for Bitcoin-based finance. The cars that drive this road are L-BTC tokens: depository-receipt-like assets that, under normal conditions, are fully backed by BTC.

Normal broke on Sunday when the hackers managed to create L-BTC tokens without first depositing BTC into Liquid Network. They exchange these newly-minted, unbacked L-BTC for $320 million in BTC that other people had deposited in Liquid Network. After withdrawing the BTC the hackers contacted Blockstream (Liquid’s developer), calling themselves “whitehats” that were willing to return “most” of the stolen funds once Blockstream had patched the bug.

As of Wednesday Blockstream had patched the bug and Liquid Network had received 85% of what was taken. But $47 million remained with the hackers. On Tuesday Liquid Network said “discussions” continue with the purported whitehats “to secure the return of the remaining funds.”

Building financial layers on top of blockchains like Bitcoin can introduce new vulnerabilities, even when Bitcoin itself remains secure. But the mechanisms through which Liquid Network minted and redeemed L-BTC had a flaw that put the service’s real BTC at risk.

Liquid Network’s software bug

At its simplest, the system vulnerability allowed the hackers to trick Liquid into accepting L-BTC that was never backed by real bitcoin. The hackers were then able to exchange that unbacked L-BTC for actual BTC held in the network’s reserve.

Think of it like a flaw in a bank’s online system that allows someone to go in and increase the balance in their account without actually depositing any money — and then withdraw that artificial balance as real cash. In Liquid’s case, the hackers created thousands of L-BTC without depositing the BTC that should have backed it, then withdrew roughly 4,000 real BTC through the network’s peg-out process.

The technical explanation comes down to a flaw in how Liquid verified transactions. Liquid uses Confidential Transactions, which hide transaction amounts and therefore require cryptographic proofs to demonstrate that transactions are valid. One of these, known as a range proof, helps ensure users cannot create assets out of thin air.

Checking these proofs takes computing power, so Liquid designed its software to cache successful verification checks to avoid unnecessarily verifying the same data again. But a flaw in the system being used to identify those cached checks meant that new data could be potentially mistaken for data that had already been approved.

The hackers exploited this by first getting valid data verified and cached, then submitting different, invalid data that pointed to the same cached result. Instead of checking the new data again, affected nodes in the Liquid network treated the data as already valid. That ultimately allowed the hackers to create unbacked L-BTC and exchange them for real bitcoin.

Discussions on-chain

The purported whitehat hackers used Bitcoin’s OP_RETURN field to communicate with Blockstream in the hours after the exploit. Sending messages back and forth on-chain, some of their communications took place in plaintext, but much was encrypted, too.

In one early, plaintext message the hackers said they would return the BTC once Blockstream had fixed the vulnerability that had allowed them to steal the funds in the first place. “The chain is under risk at latest commit,” they wrote, continuing: “make sure every node is patched.”

After Blockstream confirmed on-chain that its bridge nodes had been patched and the funds were safe to return, the actors followed through — in part. In a single transaction, they sent 3,400 BTC, roughly 85% of the amount withdrawn, back to Liquid. The remaining roughly 600 BTC was returned as change to an actor-controlled address in the same transaction.

As of Tuesday, that 600 BTC, worth roughly $47 million, remained under the actors’ control. It is unclear why those funds have not been returned. While some observers have speculated that they could amount to a de facto bounty, neither Blockstream nor the actors has publicly confirmed such an arrangement.

Blockstream has since announced it deployed updated software and is preparing the network for a restart.

FAQ

What happened to Liquid Network?

Purported white-hat hackers exploited a vulnerability in Liquid’s transaction-validation software that allowed them to create thousands of unbacked L-BTC. They then used that L-BTC to withdraw roughly 4,000 real BTC from Liquid’s reserves, worth around $320 million at the time.

What is L-BTC?

L-BTC, or Liquid Bitcoin, is a representation of bitcoin used on Liquid Network. Under normal circumstances, L-BTC is backed 1:1 by BTC held by the Liquid Federation, allowing users to move between Bitcoin and Liquid through a peg-in and peg-out process.

How did the hackers create unbacked L-BTC?

The vulnerability involved the way Liquid’s software cached certain cryptographic verification results. The attackers were able to make invalid transaction data point to a previously approved cached result, allowing it to bypass a full verification check. This enabled L-BTC to be created without corresponding BTC backing it.

How much bitcoin was withdrawn?

Roughly 4,000 of the approximately 4,200 BTC held in Liquid’s reserve was withdrawn onto the Bitcoin blockchain, worth around $320 million at the time.

Have the funds been returned?

Most have. Following an exchange of messages with Blockstream through Bitcoin transactions, the actors returned 3,400 BTC to Liquid. Roughly 600 BTC, worth around $47 million as of Tuesday, remained under their control. Neither Blockstream nor the actors has publicly confirmed what will happen to those remaining funds.

What does the Liquid hack mean for crypto security?

The incident illustrates the distinction between the security of an underlying blockchain and the infrastructure built around it. As institutions increasingly rely on sidechains, bridges, wallets, exchanges, custodians and settlement providers, assessing the resilience of those additional layers is an important part of managing digital-asset risk.

This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.