Liquid bitcoin reserve drained after authorized SideSwap peg-out

A Sept. 6 SideSwap peg-out released about 3,996 BTC after PAK validation. SideSwap traced the L-BTC to an Elements flaw. Whitehats hold about 3,998 BTC pending a patch.

Nearly 4,000 bitcoin left Liquid after a peg-out that looked authorized

On Sept. 6 a customer submitted 4,000 L-BTC — bitcoin represented on Liquid — to SideSwap’s peg-out service, which converts those tokens back into bitcoin on the main network. The request passed SideSwap’s Peg-out Authorization Key check, the credential federation signers treat as permission to release bitcoin. The Liquid Federation — the group of signers that custody the reserve — then released about 3,996 BTC, a move worth nearly $320 million as the coins left.

Those coins later sat at an address holding roughly 3,998.5 BTC. Liquid disabled its bridge nodes after the withdrawal, the software that moves bitcoin into and out of Liquid. SideSwap users, L-BTC holders, and exchanges that still quote the token are exposed until the reserve is shown to be whole again.

A valid PAK on a pre-signing defect

SideSwap said the peg-out used its valid Peg-out Authorization Key, or PAK. Liquid said that key and the other federation keys were not compromised. SideSwap said Blockstream traced the 4,000 L-BTC presented for redemption to a flaw in Elements, the software Liquid is built on.

If that tracing holds, the defect sat before the bitcoin transaction was signed. Blockchain security firm Bitslab said at least 11 of Liquid’s 15 functionaries — the federation members who must approve withdrawals — signed the release. Keys that remained in place still authorized an outflow once every signer was shown the same state and accepted it.

The 1:1 reserve was what broke

Liquid is designed to hold one bitcoin in its federation reserve for every L-BTC in circulation. In a normal peg-out, L-BTC is burned and matching bitcoin is released. SideSwap says a software bug created L-BTC with no corresponding bitcoin behind it.

Those tokens still entered a valid peg-out. Federation functionaries treated the withdrawal as legitimate and released real bitcoin. The allegedly unbacked L-BTC was burned in that process. About 3,996 BTC still left the federation wallet. Outstanding L-BTC is therefore no longer demonstrably backed one-for-one until the coins return or the books are otherwise restored.

Whitehats are holding the coins for a patch

The actors controlling the bitcoin identified themselves through on-chain messages as whitehats. They said they intend to return most of the funds once the underlying bug is fixed across the network. Whitehats are holding about 3,998 BTC pending that confirmation.

They have been communicating with Blockstream through OP_RETURN messages, data written into bitcoin transactions. Galaxy Digital research head Alex Thorn said Blockstream first asked the holder to contact its security team. The holder replied that it planned to send "most" of the bitcoin back, then added that Blockstream should fix the bug and ensure every node is patched first.

SideSwap suspended swaps, peg-ins, and peg-outs. Exchanges paused or prepared to pause L-BTC deposits and withdrawals while operators investigated.

What remains unknown

No independent technical postmortem or detailed patch description was public. The Elements root cause is still attributed to SideSwap and Blockstream and has not been independently confirmed. The scale of any eventual loss is still unknown.

The whitehats conditioned return on a network-wide fix and spoke of sending back most of the bitcoin, not all of it. Liquid’s bridge nodes remain disabled. Restart depends on showing that another batch of invalid L-BTC cannot pass the same authorization, and on a reserve reconciliation that has not yet been demonstrated.

Read on DefiEdge