Bitcoin network used by exchanges hit by $320 million vulnerability; hacker claims to be a “good guy” | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Attackers demanded via on-chain messages that the vulnerability be fixed and all nodes patched before returning the funds, but as of publication, Liquid has yet to specify when the network will restart or whether the funds can be returned.

Author: Omkar Godbole (CoinDesk)

Translated by TechFlow

TechFlow Summary: Approximately 4,000 BTC, valued at around $320 million, were withdrawn from the Bitcoin sidechain Liquid Network by “white-hat hackers,” comprising the vast majority of the consortium wallet’s 4,200 BTC reserves. The network immediately suspended transactions. Unlike most hacking incidents this year, this was not caused by a private key or password leak. Instead, a vulnerability in Elements, the open-source software that powers Liquid, was exploited, and the funds were moved through the legitimate platform SideSwap. The attackers communicated via on-chain messages, demanding that the vulnerability be patched and all nodes updated before returning the funds. As of press time, Liquid has not specified when the network will resume operations or whether the funds can be recovered.

Approximately 4,000 BTC Withdrawn, Sidechain Halts Transactions

Launched by Blockstream in 2018, Liquid Network stated that what is claimed to be the “white-hat hacker” actor withdrew approximately 4,000 of the ~4,200 bitcoins from the consortium wallet. The network is jointly governed by a consortium comprising over 80 exchanges, infrastructure companies, and asset management firms.

“Liquid wallets will be affected, and we apologize for any inconvenience caused,” Liquid Network posted on X, while suspending all new transactions. “Consortium members are actively working on the issue to restore normal network operations.”

Why This Matters

The sidechain has paused new transactions and warned that wallets may be affected while consortium members work to restore services. This matters because Liquid was originally created to address a practical pain point for exchanges: the slow transaction speed of the Bitcoin mainnet. To enable faster trade settlement, the network issues L-BTC backed by locked reserve bitcoins. With almost the entire reserve drained, concerns have been raised about the security of this model.

The Vulnerability Lies in the Software, Not Private Keys

This theft was not caused by a leaked password or private key, which is the method used in most cryptocurrency hacks this year. Instead, the stolen funds were withdrawn through SideSwap, a legitimate and authorized platform.

Subsequently, Blockstream discovered that a software bug within the Elements system essentially “generated” a portion of the involved bitcoins. SideSwap stated that it could not distinguish between coins created by the vulnerability and legitimate funds, so it processed them all identically. Other asset types on the same network (Liquid) were unaffected.

What Are White-Hat Hackers?

White-hat hackers are “ethical hackers” who identify and exploit vulnerabilities in protected systems before malicious actors can act. They typically exploit the vulnerability, transfer the funds, and then demand a fee to return them.

The Vulnerability Operates at the Node Level

According to security experts, the vulnerability in this case exists at the node level of the Liquid trading software, rather than from compromised keys or hardware modules.

Attacker Communicates via On-Chain Messages, Promises to Return Funds

According to the latest reports, the attacker is communicating with network maintainers through Bitcoin on-chain transactions, promising to return the funds once the vulnerability is fixed.

“Please fix the vulnerability first. At least on the latest commit, this chain remains under risk. Ensure that every node is patched. Once the fix is confirmed, we will safely transfer the money back,” one message read.

Recent Security Incidents Stack Up

A week prior to this theft, a lending platform affiliated with Crypto.com had its funds drained for $6 million, and in August, the Coldcard hardware wallet was also compromised. Liquid has yet to specify when the network will restart or confirm whether these bitcoins can be returned.



Click Here For The Original Source.

——————————————————–

..........

.

.