The Liquid Hack and the AI Era of Bitcoin Exploits

Last week, almost 4,000 Bitcoin was stolen without a private key ever being touched. Here’s the Liquid hack and two lessons every Bitcoiner should know.

In this article:

On Sunday, September 6th, Bitcoiners learned it was possible to steal almost 4,000 Bitcoin without ever accessing the keys that secured it.

The story behind it played out over the next few days like a made-for-TV crime drama, complete with encrypted messages exchanged on the blockchain, a cast of well-known characters, and a final arc of suspense.

Would the hacker’s demands be met, and would they return the stolen Bitcoin?

‍

The Liquid Hack - What Happened?

After a series of vulnerabilities and hacks that plagued the Bitcoin industry over the last six weeks, we were all ready to finally heave a sigh of relief. Surely it would be over now?

Alas, it wasn't.

‍

What is the Liquid Network?

Liquid, Blockstream’s side-chain that issues L-BTC in exchange for real BTC, was hacked when a self-proclaimed ‘white-hat’ hacker exploited a known vulnerability.

A federation of exchanges and firms issues L-BTC, which is used primarily for private transactions, fast settlements, and swaps between Bitcoin, Lightning, and USDT.

Liquid does have a strong use case for Bitcoin payments; however, as with any side-chain or Layer 2 built on top of the Layer 1 BTC network, there are significant trade-offs if you opt to use it.

‍

How did the Liquid network hack unfold?

The software that Liquid runs on is built and maintained by Blockstream. A flaw in the validation code allowed the hacker to trick it into creating L-BTC that wasn’t backed by any Bitcoin.

That L-BTC was then used to withdraw 95% of the BTC held in the federation’s reserves – around $320 million worth.

The Liquid federation holds the Bitcoin with an 11-of-15 multisig wallet.

The BTC transaction sent to the hacker was legitimate and signed by 11 of the 15 key holders.

So the Bitcoin network worked exactly as it was designed, and no keys were ever compromised.

The problem arose from the Liquid side chain, which was exploited to extract BTC, leaving L-BTC that was backed by nothing.

Money created out of thin air and backed by nothing? Where have we heard that before...

‍

So what did the hackers want from Blockstream?

The Liquid hackers immediately made one demand: patch the bug we just exploited, or we won’t return your Bitcoin.

[7th Sep, 03:30, Hacker: "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched."]

The hackers and Blockstream negotiated via both publicly readable and encrypted messages, attaching the text inside the blockchain’s OP_RETURN space.

When the hack occurred, the entire Liquid network was forced to pause, affecting many exchanges, wallets, and users. So the heat was on Blockstream to get the bug patched quickly.

The drama reached a crescendo the following day, when word spread that Blockstream had deployed a patch to fix the bug. Many awaited with bated breath to see if the hacker would return the Bitcoin.

[7th Sep, 09:19, Blockstream: "Bridge nodes are patched, safe to return the funds."]

[7th Sep, 12:43, Hacker: “plz confirm again that we are sending the coins back to bc1qdlld6…suhwxxr. More details about the vuln fix:]

That afternoon, Blockstream finally confirmed they had received the funds back...minus 600 BTC that the hacker kept for themselves.

‍

Can L-BTC Holders Get Their Bitcoin Out?

After a flurry of encrypted messages between the hacker and Blockstream, the hacker appeared frustrated by Blockstream's lack of progress and raised the stakes.

They published the following message, unencrypted for the world to read:

In it, they accused Blockstream of irresponsibility and dereliction of duty, and demanded a 10% bug bounty in exchange for returning the remaining Bitcoin.

At the time of writing, Blockstream has already hit back at the hackers and demanded that the remaining Bitcoin be returned - or they will involve law enforcement, and seek legal recourse.

While the Liquid network has resumed operations, the L-BTC to BTC swaps remain paused. For L-BTC holders right now, there is no exit at all.

Co-founder and CEO Adam Back – who was very vocal during the BIP-110 conflict - remained silent on the incident until four days after it broke, prompting X followers to ask ‘When will Adam be Back?’

Meanwhile, the Bitcoin network remains oblivious to the Liquid network's trials and tribulations. It continued to confirm transactions and mine a new block every 10 minutes throughout the entire incident.

Did you know that we also cover breaking events in Bitcoin, like the Liquid hack, on our YouTube channel?

If you haven’t checked it out already, we talked about this incident - plus other news affecting Bitcoiners - on our weekly Live and Bitcoin Banter shows.

Check out a replay of last week’s Live
here

See this week’s podcast with the founder of Seedsigner here

Watch our latest Bitcoin Banter episode here

‍

So who does the Liquid Network hack affect?

Well, Blockstream for starters. They are staring down the barrel of having to make up the $50 million shortfall themselves, or risk having the entire project collapse.

And as we have seen in the past, when various crypto exchanges, platforms, and projects have collapsed, it’s always the end user - the individual left holding the worthless token - that suffers the most.

Trust in the Liquid network has already been eroded, possibly past the point of no return.

And with reserves short by almost 600 BTC, each L-BTC is backed by only 85% of one Bitcoin.

The network cannot allow swaps from L-BTC back into BTC without 1:1 backing because Blockstream would be risking a bank-run scenario.

Nobody wants to be the last one holding the bag when the music stops.

‍

What are the lessons for Bitcoiners from the Liquid hack?

1. AI is making code exploits faster to find.

The first lesson from this hack is that as AI models become increasingly sophisticated and new capabilities come online, the risk of flaws being exploited by hackers becomes exponentially more likely.

Perhaps coincidentally, this hack came three days after the release of OpenAI’s GPT-6 Astra. This new model is rated critical for cybersecurity capabilities and is marketed as the first model able to find unknown vulnerabilities and exploits unaided.

While there is no evidence that GPT-6 or any other AI model was used to find and exploit this vulnerability, it follows a pattern we have seen across the industry lately.

And this won't be limited to the Bitcoin space. While it may show up earlier here because of the potential rewards for hackers, it will soon affect every aspect of your digital life.

Passwords, email, laptops, phones, SIM cards, routers, smart home devices, bank and brokerage logins, apps – almost anything that runs software or firmware.

Everything needs to be locked down tight and protected from potential attacks by bad actors. Unfortunately, we no longer live in a world where you can secure your bank account with ‘mydog123’.

So the Liquid hack demonstrated that a vulnerability or attack vector can emerge where you least expect it, and it may not look anything like the last one.

‍

2. Every trusted third party is a point of failure.

The second lesson from the Liquid hack is that any time you involve a trusted third party in your Bitcoin custody, you risk losing access to your Bitcoin.

And yes, this includes side-chains like L-BTC, not to mention exchanges, lenders, Wall Street products, treasuries, and banks.

If someone is holding your Bitcoin on your behalf, you are looking at a trusted third party.

And trust is exactly what Bitcoin was designed to remove.

If you need trust, your Bitcoin isn't 100% safe. The only way to properly own and control your Bitcoin is to have it in a secure self-custody setup.

‍

So what can YOU do to protect yourself?

At The Bitcoin Way, this is what we do, all day every day. We help people secure their Bitcoin in self-custody, with plenty of redundancy to ensure there is no single point of failure.

In this brave new world, attackers have increasingly sophisticated ways to break flawed code, steal passwords and personal data, and guess weak seed phrases.

This is not a world you should try to navigate alone.

You need to be armed with the tools to defend against potential security breaches, and the right team behind you in case anything unexpected happens.

And make sure you pick your team wisely. If they ask for your personal details, conduct KYC, or hold one of your keys, proceed very, very cautiously. We take our clients’ privacy very seriously.

If you would like to learn more about our self-custody or cybersecurity services, get in touch with us today.

You can book a 30-minute introductory call to discuss your needs and concerns with one of our expert team members and find out whether our services are a good match for you.

Pursue your
freedom today

Every journey begins by taking the first step. Book a free 30-minute consultation with one of our experts and let’s start securing your future.