InternationalItaliano中文
IL PROGRESSO

Independent journalism on global markets, technology, and the forces reshaping the world economy

Ufficio Emissioni · VeneziaEmissione N. 1412
Home /Technology /Emissione
Technology01 MIN

Liquid Network Halts After $319M Bitcoin Heist Exposes Sidechain Flaws

Liquid Network, a Bitcoin sidechain developed by Blockstream, has suspended its operations following the theft of nearly 4,000 Bitcoin, valued at approximately $319 million. The attacker exploited the network’s Peg-out Authorization Key (PA…

Liquid Network Halts After $319M Bitcoin Heist Exposes Sidechain Flaws

Liquid Network, a Bitcoin sidechain developed by Blockstream, has suspended its operations following the theft of nearly 4,000 Bitcoin, valued at approximately $319 million. The attacker exploited the network’s Peg-out Authorization Key (PAK) mechanism, a critical component of the system’s two-way peg that allows users to move Bitcoin between the main chain and the sidechain. While the entity claiming responsibility has been labeled a “white hat” hacker, the incident has raised serious questions about the security architecture of federated sidechains and the broader custody risks inherent in layer-two solutions.

The exploit occurred when the attacker managed to bypass the network’s whitelist controls, which are designed to restrict which addresses can receive withdrawn Bitcoin. Under normal operations, a peg-out transaction requires authorization from 11 of the 15 functionaries that manage the network’s multisig wallet. However, in this instance, the attacker was able to initiate a transaction that drained the wallet of nearly all its holdings, leaving a balance of just 207 BTC. The funds were subsequently moved to a single address, where they have remained unmoved, a detail that has fueled speculation that the attacker may indeed be acting in good faith rather than seeking immediate liquidation.

Blockstream has confirmed that the PAK itself was not compromised, suggesting the vulnerability lay elsewhere in the transaction approval process. The company has stated that the L-BTC involved in the exploit was created through a bug in the Elements software, the underlying codebase for Liquid. This distinction is crucial, as it implies the attacker may have minted new tokens rather than stealing existing ones, a nuance that could have significant implications for how the network’s liabilities are calculated and who bears the ultimate loss. The team has paused bridge nodes and is actively investigating the security hole, but the damage to user confidence may already be done.

The timing of the incident is particularly inopportune for the broader cryptocurrency market, which has been showing signs of renewed strength. US spot Bitcoin ETFs have recorded their strongest three-week inflow stretch of 2026, attracting $986.9 million in the week ending Friday and bringing cumulative inflows over that period to $3.8 billion. Total net assets across the funds now stand at $101.3 billion, a figure that suggests institutional demand remains robust despite the persistent volatility. Thursday alone saw $730.9 million in net inflows, the strongest single-day showing since January 14. These numbers indicate that while the Liquid hack has captured headlines, it has not yet deterred the institutional capital flowing into regulated investment vehicles.

The contrast between the ETF inflows and the Liquid exploit highlights a growing bifurcation in the market. On one hand, institutional investors are increasingly favoring regulated, custodially secure products like ETFs. On the other, the decentralized finance ecosystem continues to grapple with the inherent risks of self-custody and complex multi-party computation. The Liquid incident serves as a reminder that even well-funded, technically sophisticated projects can fall victim to unforeseen vulnerabilities. The fact that the attacker has not yet moved the funds offers a sliver of hope for recovery, but the structural weaknesses exposed by the breach will likely require a fundamental redesign of the network’s security model.

The broader implications extend beyond Liquid itself. The incident reignites the debate over the trade-off between security and decentralization in layer-two solutions. Federated sidechains like Liquid rely on a trusted set of functionaries, a design that introduces a single point of failure even if the multisig threshold is high. The exploit demonstrates that such systems are only as secure as their least-protected component, and that sophisticated attackers will target the seams between different layers of the architecture. For users, the lesson is stark: even assets bridged to a sidechain are not immune to compromise, and the risk profile of such assets differs fundamentally from those held directly on the Bitcoin mainnet.

As the investigation continues, the market will be watching closely to see whether the funds are returned and whether Blockstream can restore trust in the network. The incident has already sparked renewed calls for more transparent auditing and more rigorous stress-testing of sidechain security. For now, the Liquid exploit stands as a cautionary tale about the fragility of trust-minimized systems, while the concurrent ETF inflows suggest that institutional capital is undeterred by the persistent risks of the underlying technology. The two narratives may seem contradictory, but they reflect a market that is maturing in fits and starts, learning hard lessons about security even as it embraces new avenues for growth.

Source & Credits

Written for Il Progresso by Zhicheng Wang.

↑ Torna alla prima pagina