Alarm bells are ringing across the Bitcoin ecosystem after approximately 4,000 BTC, valued at $320 million, exited Liquid, the Blockstream sidechain, following the exploitation of a severe network software vulnerability. Specifically, SideSwap, a member of the federation operating a peg-out service, reported that a client transmitted 4,000 L-BTC at 14:05 UTC. SideSwap proceeded to burn these tokens under valid authorization and, 23 minutes later, the federation disbursed 3,996 BTC. Liquid stated that funds were transferred via SideSwap's Peg-out Authorization Key, yet neither this key nor any other federation key was compromised.
SideSwap similarly declared that none of its internal systems were breached, pointing instead to a bug within Elements, the underlying software powering Liquid. Blockstream has not clarified the exact nature of the bug, despite a patch having been committed to Liquid's underlying code base five weeks earlier. No unauthorized withdrawal occurred directly from the wallet itself. Instead, an attacker managed to mint L-BTC without corresponding Bitcoin collateral and subsequently redeemed them via what appeared to be a completely standard peg-out procedure. The wallet held approximately 4,200 BTC prior to Sunday's incident and roughly 200 BTC immediately following it.
In communication with alleged "white hats"
The perpetrators left an on-chain message stating: "we are whitehats. Contact us on chain." Blockstream responded an hour later providing an email address, establishing an exchange of PGP-signed messages embedded directly within Bitcoin transactions.
The hackers offered to return the vast majority of the funds but stipulated one condition: the bug must be fixed first, arguing that the blockchain remains exposed under its most recent code release and requiring every network node to update. Blockstream's brief reply, "Yes, thank you," acknowledged the initial offer to return funds and was confirmed in the exact same block as the hackers' message setting that condition. Ledger Chief Technology Officer Charles Guillemet initially observed that "white hats don't drain a bridge and then ask for on-chain contact," drawing parallels to the high-profile Ronin and Euler cryptocurrency exploits. He briefly raised the possibility that the attackers were individuals "playing intensively with recent LLMs," though his stance hardened following the insistence on fixing the bug prior to returning assets.
As he noted, white hat conventions "have evolved," adding:"Now they steal the money and refuse to return funds until the vulnerability is patched..." Former Blockstream Chief Security Officer Samson Mow, who shared the communication timeline, estimates that the address controlled by the hackers holds roughly 3,998.5 BTC. Other digital assets hosted on Liquid, including USDT, DePix, and tokenized real-world assets, remain entirely unaffected. The underlying Bitcoin mainnet itself was not impacted.
www.bankingnews.gr
Σχόλια αναγνωστών