Reviewing the Liquid Network Security Incident

On September 6th, an attacker successfully exploited a software vulnerability within Blockstream's Liquid Network. This breach allowed the individual to generate approximately 3,996 unbacked L-BTC. The attacker subsequently used a federation member to exchange these unauthorized tokens for actual bitcoin, ultimately draining roughly $319 million from the reserve of the federation.

It is important to emphasize that no private keys were compromised during this event. The issue stemmed entirely from a flaw in the transaction verification process, which inadvertently permitted a counterfeit transaction to be approved.

We have put together a detailed summary to help you understand the full scope of the situation. Our document explores exactly how the attack unfolded and reviews the responsive actions taken by Blockstream. Furthermore, we evaluate the important question of whether Nexus Mutual would have offered coverage for this particular incident.

You can access the complete analysis by visiting this link: https://nexusmutual.io/blog/liquid-network-incident-report