Liquid Network Exploit Results in $320 Million Loss
A bug in Elements allowed attackers to create unbacked L-BTC and withdraw BTC from Liquid.
Purported white-hat attackers exploited a vulnerability in Elements, the underlying software of the Liquid Network, to generate approximately 4,000 unbacked L-BTC. They then utilized SideSwap’s normal peg-out flow to withdraw around 4,000 BTC, equivalent to about $320 million, from the Liquid Federation wallet. Importantly, no private keys were compromised during this incident.
In response to the exploit, the Liquid sidechain has been paused to prevent further unauthorized transactions. The mechanism of the attack involved manipulating the peg-out process, which allowed the attackers to convert the unbacked L-BTC into BTC. This incident highlights a significant flaw in the Liquid Network's software that was exploited to facilitate the withdrawal of a substantial amount of funds.
