Blockstream’s sidechain Liquid resumed block production on Thursday, about four days after a person claiming to be a white hat hacker drained close to 4,000 BTC from its federation wallet and then handed back most of it. The restart is pertinent to anyone with Liquid Bitcoin (L-BTC) or stablecoins on the network.
Funds have been suspended since Sunday, and about 600 BTC still in the attacker’s hands represents a hole in the reserve backing those tokens.
In a status update posted at 10:00 UTC, the @Liquid_BTC account said that block production had resumed “without transactions” as a precautionary measure while the team monitors for full stabilization.
Bridge and functionary nodes of Liquid now have the requisite software patches live. Functionary nodes are signing and validating blocks as they ought.
Peg operations are switched off while the network rebuilds its BTC-to-L-BTC reserve.
It all commenced on Sunday, September 6, when hackers claiming white-hat status withdrew about 4,000 BTC, worth about $320 million, from the Liquid Federation wallet. That was about 95% of the wallet’s ~4,200 coin balance.
At the time, Cryptopolitan reported that the withdrawal was made using SideSwap’s peg-out authorization key, which was never stolen.
Blockstream later said the issue was induced by a flaw in Elements, the open-source software underpinning Liquid, that allowed the creation of invalid L-BTC and its redemption via the normal path as if it had been fully backed.
The team shipped an emergency fix, Elements v23.3.4, one day before restart, hardening the cache keys used for range proofs to close the proof verification vulnerability connected to the theft.
After Blockstream signed an on-chain note saying, “Bridge nodes are patched, safe to return the funds,” the actors returned 3,400 BTC, about $269.2 million at the September 7 conversion rate. That left some 598.5 BTC outstanding, somewhere around $46 million to $47 million depending on the current price.
On September 9, the anonymous hacker publicly blasted Blockstream’s spending, claiming the company had allocated only $1.5 million to protect $5 billion in assets.
“Your dereliction of duty is obvious,” the hacker wrote, warning that the rest of the coins would stay missing unless a 10% bug bounty was paid.
“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” added the threat actor.
Blockstream founder and CEO Adam Back reassured holders that the L-BTC peg will be honored one-for-one, meaning users can redeem their tokens for the same amount of Bitcoin on the base layer.
“Do not panic sell OTC,” wrote Back on X.
He did not express how the ~600 BTC shortfall will be covered when peg-outs reopen or provide a timeline for restoring peg-in and peg-out services.
The network moved again about 10 hours later. A status update posted at 19:55 UTC verified that transactions had resumed, while peg-outs are unavailable.
If you're reading this, you’re already ahead. Stay there with our newsletter.