Liquid drained of 95% reserves; the hacker only agreed to return 85%
On September 6, the Liquid network disclosed an Elements consensus and asset verification vulnerability. The attacker minted about 4,000 L-BTC tokens with no real underlying assets, then went through SideSwap’s normal redemption process to swap these “air L-BTC” into 3,996.01834922 genuine BTC, taking them directly from the Liquid Federation. At the time, the value was about $320 million; the reserve balance dropped from roughly 4,207 BTC to around 197 BTC—draining 95%.
The Bitcoin mainnet itself was not compromised. Of the Federation’s 11/15 signing members, those who were supposed to sign did sign—so the signature mechanism was functioning normally. The issue was entirely in Liquid’s sidechain Elements validation logic. SideSwap also stated that its PAK system was not breached; it was only used as a normal redemption channel. Other assets such as USDT were unaffected because they are never backed by that peg wallet. However, the network’s pause mechanism still froze the entire transfer and liquidity.
As for what happened next: the attacker used an on-chain OP_RETURN message to claim they were a white-hat, demanding that the vulnerability be fixed before returning the funds. The two sides negotiated across the blockchain for several rounds. On September 7, the attacker returned 3,400 BTC, keeping 598.5 BTC—worth about $47 million at the time—as an effective “finder’s fee.” That ratio was no longer up for discussion; in the end, the attacker only returned a sad emoji.
This kind of “hack you, then voluntarily negotiate part of the return” is no longer new in DeFi and cross-chain over the past couple of years. But the larger the amounts involved each time, the weaker the deterrent effect of this “post-hack protection fee” approach on the whole industry becomes—if the cost of a vulnerability is always “return the bulk, keep a substantial split,” does that count as effectively encouraging more people to go looking for bugs?
#Liquid #Blockstream #BTC #侧链安全 #白帽黑客