Hackers stole about $320 million worth of bitcoin over the weekend from a blockchain platform called the Liquid Network.
In a somewhat unusual development, the attackers returned most of the haul earlier today. They retained 598 of the 4,000 stolen bitcoin, or about $47 million worth. The hackers stated that they would keep the funds as a “bounty” for bringing attention to a vulnerability in the Liquid Network.
The Liquid Network was launched in 2018 by a venture-backed cryptocurrency company called Blockstream Inc. It’s a layer two Bitcoin network, a blockchain built on the infrastructure that powers Bitcoin. Such blockchains are also known as sidechains.
Bitcoin processes user transactions through a decentralized process. When a bitcoin holder moves funds, thousands of user-operated servers called full nodes verify the authenticity of the transaction. From there, a user with bitcoin mining hardware formalizes the transaction by performing an energy-intensive processing task.
The Liquid Network replaces Bitcoin’s transaction approval process with a more centralized workflow. The task of verifying payments is performed by a group of about 80 organizations. They include cryptocurrency wallet providers, exchange operators and various other industry players. At any given time, only about 15 of the organizations play an active role in verifying transactions.
The Liquid Network also differs from Bitcoin in other ways. Users can’t view the value of one another’s transactions. Additionally, a system called SideSwap makes it possible to move funds to and from other blockchains. That system was at the center of the weekend bitcoin heist.
Users sign up for the Liquid Network by depositing bitcoins into SideSwap. The system moves the bitcoin to a virtual vault for safekeeping and issues a quantity of platform-specific stablecoins with equal value. When a user wishes to move funds off the Liquid Network, SideSwap returns the bitcoins that the user deposited.
The process through which SideSwap moves cryptocurrency involves a piece of data called the peg-out authorization key, or PKA. The Liquid Network’s maintainers stated the hackers used the PKA to steal the bitcoins. At the same time, the maintainers claim that the PKA was “not compromised.”
SideSwap’s developers wrote on X that the hackers exploited a flaw in Elements, an open-source project that underpins the Liquid Network. It powers the sidechain’s centralized transaction approval workflow and other key features.
The 4,000 coins stolen by the hackers represented about 95% of the Liquid Network’s Bitcoin reserve. Other cryptocurrencies stored on the sidechain were not impacted. Shortly after the breach, the hackers embedded a message to Blockstream in a public Bitcoin transaction log. They informed the company that they would return most of the stolen cryptocurrency once it patched the vulnerability.
The breach is the latest in a string of recent cyberattacks against cryptocurrency platforms. Hackers stole an estimated $136.3 million across 50 breaches in August.





