Skip to the article
Mining, Hashrate And Network Security Times

Mining economics and network security

Network Security

Liquid Resumes Empty Blocks After $320M Bitcoin Withdrawal

Liquid’s reserve loss did not weaken Bitcoin’s hashrate, but it exposed how federation software can bypass controls that mining security never supplies.

By Mining, Hashrate And Network Security Times Editorial 3 min read

Liquid Resumes Empty Blocks After $320M Bitcoin Withdrawal

On September 6, Liquid Network paused after purported white-hat hackers exploited a transaction-validation flaw and withdrew roughly 4,000 BTC, then worth about $320 million, from its federation reserve. The immediate costs fell on L-BTC holders, exchanges and service operators: transfers stopped, liquidity became inaccessible and the federation assumed the expense of patching and reconciling the network. Bitcoin’s hashrate and miner revenue were not directly affected.

By September 10, the actors had returned 3,400 BTC, while about 598.5 BTC remained under their control. Blockstream reported that required functionary and bridge-node updates had been deployed and block production had resumed without transactions. Peg-ins and peg-outs remained suspended while the federation worked to restore the BTC-to-L-BTC reserve.

How did the Liquid Network exploit work?

The reserve failed because Liquid accepted invalid issuance before its peg-out controls encountered what appeared to be legitimately held L-BTC. Liquid uses cryptographic range proofs to validate confidential transactions and caches successful checks to reduce repeated computation. Reporting on the flaw indicates that manipulated data could be associated with a cached valid result, causing affected nodes to skip a fresh verification and accept unbacked L-BTC.

The actors sent 4,000 L-BTC through SideSwap’s authorized peg-out service. SideSwap burned the tokens, and the federation released approximately 3,996 BTC through the ordinary withdrawal process. Liquid said the SideSwap Peg-out Authorization Key was not compromised. That distinction matters: the 11-of-15 multisignature system appears to have signed according to its rules, but those rules consumed corrupted sidechain state.

  • Roughly 4,000 of the reserve’s approximately 4,200 BTC were withdrawn.
  • The withdrawal represented about 95% of reported bitcoin backing.
  • The actors returned 3,400 BTC after bridge nodes were patched.
  • No agreed bounty for the remaining bitcoin has been publicly confirmed.

Did the Liquid exploit weaken Bitcoin mining security?

No: the exploit neither reduced Bitcoin’s hashrate nor defeated its proof-of-work consensus. Bitcoin miners ordered and confirmed a transaction carrying valid federation signatures. Their security budget protected that transaction against reorganization and double-spending; it could not determine whether Liquid’s software should have authorized it.

This is the boundary between mainchain security and bridge security. Bitcoin distributes transaction ordering across miners competing with specialized hardware and electricity. Liquid instead relies on designated functionaries, an 11-of-15 signing threshold and software that translates sidechain events into mainchain withdrawals. More hashrate, cheaper power or a newer mining fleet would not have corrected a false validation result inside that translation layer.

What should operators require before allocating capital to Liquid?

Operators should price L-BTC as a federation and software exposure, not as bitcoin carrying unchanged mainchain security. The normal operating benchmark was one L-BTC backed by one BTC; once unbacked tokens could trigger real withdrawals, that assumption failed even though Bitcoin itself continued settling blocks normally.

Capital committees should require a public root-cause account, evidence that all consensus-relevant nodes reject the exploit, an independently reconciled reserve and clear treatment of the outstanding 598.5 BTC. They should also budget for liquidity interruptions by limiting bridge concentration and maintaining alternative settlement routes.

The return of 85% of the bitcoin reduces the prospective loss, but voluntary repayment is not a security control, and “white hat” remains the actors’ characterization rather than a verified status. The verdict is narrow but firm: mining security worked, while Liquid’s federation software failed at the point where sidechain accounting became spendable bitcoin. Empty-block production shows recovery has started; it does not yet prove that the network is ready to carry capital again.

Filed under

  • Network Security