4,000 BTC Drained: The Liquid Network Exploit Nobody Saw Coming
Blockstream's Liquid sidechain got hit hard, attackers exploited a bug in the Elements software to mint unbacked L-BTC, then converted it into real BTC via SideSwap's peg-out service, draining the federation wallet from ~4,200 BTC down to ~197 BTC in about 30 minutes. No federation multisig keys were touched, the flaw sat upstream, in the code that validates transactions before they even reach the signers.
The attackers called themselves white-hats and returned ~3,400 BTC after the patch went live. Roughly 598 BTC (~$47M) is still sitting in their wallet as a "self-appointed bounty", which, let's be honest, isn't the same as a disclosed bug bounty program.
The real takeaway: L-BTC is a wrapped asset, not native Bitcoin. Its security depends entirely on the federation's code and custody model, closer to WBTC than to Bitcoin L1. If you're holding wrapped BTC anywhere, know exactly what's backing it.
What's your take, does this kill confidence in Bitcoin sidechains, or is a same-day patch actually a good sign?
#Bitcoin #BTC #CryptoSecurity #Crypto