Nearly 4000 coins $BTC were taken, and many people’s first reaction was that the mainnet had been compromised. It wasn’t.
What was compromised was Blockstream’s Bitcoin sidechain, Liquid. On the evening of September 6, someone submitted a redemption for 4000 L-BTC to SideSwap. 23 minutes later, the federation wallet sent out 3996.018 real $BTC , worth about $320 million. Reserves dropped from about 4200 coins to about 197, equivalent to 95% of the pre-incident pegged amount.
The official statement says the Peg-out authorization key was not lost. The problem was with the Elements node software. A vulnerability first created a batch of abnormal L-BTC out of thin air; most nodes accepted it, and SideSwap could only see coins that had already passed verification, so it destroyed and redeemed them through the normal process. Confidential transactions hide the amount, and nodes rely on commitments and range proofs to preserve conservation. Once consensus breaks, the subsequent redemptions look completely legitimate in the system.
The other party left a message on-chain: we are whitehats. contact us on chain. Later, they also used OP_RETURN and PGP to communicate with Blockstream, demanding that a patch be applied first, that all nodes be upgraded, and then that most of the money be returned. As of this writing, the money has not been returned.
I’m not going to make a final call on the word whitehat. Taking the money first and talking later feels more like a forced bounty negotiation. Ledger’s CTO has also publicly questioned this kind of operation.
For traders, the conclusion is very concrete. If you hold L-BTC, or use Liquid channels for deposits and withdrawals, treat this channel as temporarily broken for now. Sidechains, federation multisig, and wrapped assets do not share the same security boundary as the mainnet. The mainnet not being breached does not mean the layer you thought was anchored to it can’t break.
How much of those 4000 coins will ultimately come back will decide not only whether Liquid can restart, but also whether the federation settlement layer is still worth trusting.
Do you think this counts as a rescue, or extortion? The above is only personal observation and does not constitute investment advice.
#BTC sidechain security
What was compromised was Blockstream’s Bitcoin sidechain, Liquid. On the evening of September 6, someone submitted a redemption for 4000 L-BTC to SideSwap. 23 minutes later, the federation wallet sent out 3996.018 real $BTC , worth about $320 million. Reserves dropped from about 4200 coins to about 197, equivalent to 95% of the pre-incident pegged amount.
The official statement says the Peg-out authorization key was not lost. The problem was with the Elements node software. A vulnerability first created a batch of abnormal L-BTC out of thin air; most nodes accepted it, and SideSwap could only see coins that had already passed verification, so it destroyed and redeemed them through the normal process. Confidential transactions hide the amount, and nodes rely on commitments and range proofs to preserve conservation. Once consensus breaks, the subsequent redemptions look completely legitimate in the system.
The other party left a message on-chain: we are whitehats. contact us on chain. Later, they also used OP_RETURN and PGP to communicate with Blockstream, demanding that a patch be applied first, that all nodes be upgraded, and then that most of the money be returned. As of this writing, the money has not been returned.
I’m not going to make a final call on the word whitehat. Taking the money first and talking later feels more like a forced bounty negotiation. Ledger’s CTO has also publicly questioned this kind of operation.
For traders, the conclusion is very concrete. If you hold L-BTC, or use Liquid channels for deposits and withdrawals, treat this channel as temporarily broken for now. Sidechains, federation multisig, and wrapped assets do not share the same security boundary as the mainnet. The mainnet not being breached does not mean the layer you thought was anchored to it can’t break.
How much of those 4000 coins will ultimately come back will decide not only whether Liquid can restart, but also whether the federation settlement layer is still worth trusting.
Do you think this counts as a rescue, or extortion? The above is only personal observation and does not constitute investment advice.
#BTC sidechain security