ErgoBTC spotted this:
@06bc1a977d noticed that Liquid stopped mining blocks about 5 hours ago (block 4050335) #1563524
pull down to refresh
ErgoBTC spotted this:
@06bc1a977d noticed that Liquid stopped mining blocks about 5 hours ago (block 4050335) #1563524
The liquid dashboard just updated:
oof!
that is the word of the day.
Just the day?
year?
Exactly. Hate 2026.
Can I do a spot swap for 0.04 BTC == 1 LBTC right now?
just pulling legsdeleted by author
Let's hope it stays at that!!!
aaaand...its gone
I saw speculation that this may have been due to a consensus bug in Liquid.
Mempool's liquid explorer got stuck earlier today (#1563524), but Blockstream's liquid explorer did not.
@wiz notes that mempool was running a different version of Elements than Block stream.
source
Bitmex Research identifies a transaction that didn't work on Wiz's liquid mempool explorer but did work on blockstream's:
https://blockstream.info/liquid/tx/f24a4b179b5cc7e88b25a763911f7cbdf2bf45d1d1b5ab611e94461cef0a183f?expand
source
Was this the same bug that was found on peerswap weeks ago?
This one?
#1539582
Image got deleted, so it's harder to track down.
Also, this:
source
There you go. Security measures implemented, and circumvented.
@BlokchainB those your guys?
Indeed they are
they just converted 4k fake BTC to real BTC from the liquid peg by circumventing a security measure 😂
Let’s see if @sideswap_io will come on SN and give a better explanation
Looks like Stutxo has an idea what happened:
source
Yes. I came to the same conclusion.
https://gist.github.com/1440000bytes/211ac92dd4433bb1a2e674bf0ff7db2e
now the hackers want to be contacted on signal:
https://mempool.space/address/bc1q7le6nr37p892jzlyugr5sl29pfcg27xl77eafu
and a statement from Blockstream:
source
Sideswap says it wasn't their code?
source
"Elements bug" is very curious.
What does that mean? Another weak RNG issue? But Blockstream and others have said that keys are secure....so maybe whats going on is elements had a bug that allowed faulty / fake peg-out transaction and that this exploit was accepted by all other element-nodes on the network....so basically they crafted a fake peg-out that somehow bypassed checks and other elements nodes also accepted. The proverbial door and lock are secure but window is wide open.....
@calle
I doubt it has to do with compromised keys.
That’s my team!! 👍
Oh boy... may as well asked for a DM on LinkedIn.
holy! I guess federated multi-sig was security theatre all along, if you can just spoof the whitelist and get such a massive transaction processed, wow! Was every member asleep at the wheel?
So all users, all wallets, and all exchanges balances are now unbacked, this network is fried!
Darth is somwhere laughing his ass off right now
Comment from the SideSwap telegram chat!
Statement on today's Liquid incident
Today at 14:05 UTC a customer sent 4,000 L-BTC to the SideSwap peg-out service. Our service processed it like any other order: the L-BTC was burned on Liquid with a valid peg-out authorisation, and at 14:28 UTC the Liquid Federation paid 3,996 BTC to the customer's Bitcoin address.
Blockstream has since established that the L-BTC in that order was created through a bug in the Elements software. As Blockstream stated, SideSwap's peg-out authorisation key was not compromised, and nor was any SideSwap system. Our service had no way to tell those coins from any other L-BTC.
What this means for you:
• Your wallet is not affected. SideSwap is non-custodial and your assets are controlled by your own keys. There is nothing you need to do.
• Liquid is paused by the Federation, so swaps, peg-ins and peg-outs are paused in SideSwap until the network resumes.
• Peg-outs already paid on Bitcoin are complete. If you have a peg-in or peg-out that has not completed, email hello@sideswap.io with your transaction id and we will handle it individually.
Blockstream and the Liquid Federation are leading the network-level response, including how and when the network restarts. We will not speculate on that.
The team is offline overnight. We will answer questions here and by email from tomorrow morning (UTC). Please do not send any new peg-in or peg-out deposits until we say services are back.
Statements: x.com/Liquid_BTC and x.com/side_swap
Liquid was always a shitcoin.
This re-enforces and just proves further that bitcoin is secure.
With the inflation bug that was exploited in monero and now liquid, also rumored zcash in the past; the theme is that confidential transactions introduce complexity and a large attack surface for exploitation. What many said was one of Bitcoins flaws (lack of onchain privacy) actually is its strength. The trade-off of going without confidential transactions onchain, in exchange for solid transparency and security.
Privacy can still be achieved via coin control, coinjoin, payjoin, coinswap, lightning. This liquid hack only proves further how secure Bitcoin really is. Bitcoin does not use confidential transactions which resulted in hacks of things which do like monero, Liquid, (zcash?). I was a fan of liquid network, though going forward I lack confidence in confidential transactions on anything.
Seem blockstream.info/liquid/ is still stacking blocks
Oooooo damn
lol, couldn't happen to a nicer bunch...
The lack of circuit breakers for large transactions or many small ones adding up at SideSwap is almost as much of a piss-off as the bug leading to the extra LBTC here.
A real shame. After big blocks lost in the blocksize war I liked the liquid side chain for handling small amounts of bitcoin to reduce pressure and incurring of fees on layer 1. Peg-ins were a nice way to dispose of smallish UTXOs vs the privacy loss of consolidating and there were some privacy benefits to consolidating LBTC on Liquid.
Several things about lightning don't work great for me, I can't keep a watchtower online all the time and rocking a mobile wallet + the data usage as a monitoring node is not something I want to do as I'm trying to resist the smartphonification of everything.
Liquid was nice for spending smaller amounts on lightning from time to time because there were exchange smart contracts out there like Boltz (gone but there was swapmarket) where you could pay lightning invoices with LBTC and even make lightning invoices.
Another thing about lightning is having to maintain multiple channels to have workable liquidity. Not really a great end-user technology, a layer to build on.
Even if I'm keeping a channel open, the smart contracts for trading lightning-LBTC were nice as I could leave a lightning channel in a relatively low balance state (less worry about the other party in the channel / watchtower needs) -- I could then fund it quickly and easily when I needed it.
Even if there really is a whitehat here who gives everyone a happy ending, Liquid ecosystem will be pretty damaged.
I guess we've got the world of bitcoin eCash as a substitute (cashu, fedimint). Instead of one really big federation with support from Blockstream it entails working with a bunch of smaller custodians and micro federations. Painful if needing to spread nuts across them / figuring out how much trust they are worthy of.
#1563674
Also no updates on boltz swaps infrastructure? I am shocked how few people are upset by this. I guess everyone holds ETFs now?
There was an update that the company was changing hands, but yea dont think ive seen anything on the infra.
Website isn't even up :-\
This is the end of Liquid. I can't see how anyone will trust them going forward and how tokens like USDT can be salvaged. So much incompetence by Adam Back's SideSwap. Shit, shit, shit.
People that were using this to begin with probably don't have much capacity to learn anything from it.
In this era of AI, I think becoming an ossification-ist is going to be the only reasonable solution.
Ossification: if it ain't broke don't fix, but also; when it breaks, we can't fix
Wrong, things still get fixed when there's an consensus imperative. The script kids just don't get their misguided wants.
Always has been
Sigh I was a fan of liquid and Coldcard. What’s next? My NWC gets compromised and all my sats are drained?
Coldcard: -100%
Liquid: -100%
01/2028 ASST Calls: +130%
My bingo card is fucked lol.
Hang in there! This stuff sucks, but we come out harder.
What else are you a fan of? jc
Food
Doesn't that happen once a month?
Something isn't making sense in my grug brain though:
This is the Liquid federation wallet address listed on Liquid's explorer:
bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr
If you check it out on mempool.space it shows that there is a transaction spending out of it to a new address:
bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte
Now there is a new transaction at this address with OP_RETURN "please contact security@blockstream"
Did the original transaction spend funds back into the liquid federation?
Shall I get the popcorn?
If you work at Blockstream you may need something stronger
It looks like the hacker took funds, sent to address they control... then blockstream sent them another 1000 sats asking they initiate contact.
Looks bad.
So my liquid wallet currently unchanged... So I assume that any l-btc in there is basically backed by zero btc. And frozen till they figure out what to do.
Yes
Seems they stopped blocks hours ago
#1563524
Every day we stray further from his light
https://m.stacker.news/155293
deleted by author