Alex Thorn, head of firmwide research at Galaxy Digital, said Liquid’s approved-address withdrawal restriction did not stop the people behind the Sept. 6 incident from moving bitcoin out of the sidechain.
Liquid is a Bitcoin sidechain operated by a federation of exchanges and companies. Real bitcoin is held in a shared wallet and used to back the L-BTC token that circulates on the network.
Exploit led to roughly 4,000 unbacked L-BTC
According to an analysis by security firm CertiK, someone exploited a bug in Liquid’s software on Sept. 6 and created roughly 4,000 L-BTC that had no bitcoin backing. The attacker then converted those tokens into real bitcoin through Liquid’s own withdrawal system.
Unchained reported that the withdrawal drained about 95% of the bitcoin pegged into Liquid, and the sidechain was frozen the same day.
Liquid said the parties responsible describe themselves as white-hat hackers.
Liquid documentation says peg-outs require registered PAK entries
Liquid does not allow just anyone to move bitcoin off the sidechain. To exit, a user returns L-BTC and the federation releases the matching BTC on the Bitcoin network, a process Liquid calls a peg-out.
The network’s developer documentation says a peg-out requires a Peg-out Authorization Key, or PAK, and states that only users with registered PAK entries can peg out. The stated purpose is to make sure that even if federation operators were compromised, user funds could not be redirected to attacker-controlled addresses.
Even so, the coins ended up at an address controlled by the people who took them.
Thorn says the restriction never actually bound them
Speaking on Unchained’s Uneasy Money podcast, Thorn said the restriction never actually applied in a way that stopped the attackers.
Liquid’s documentation says most users cannot complete that swap on their own and that the general public typically goes through a federation member or an exchange. It names SideSwap and Bitfinex as examples, with the exchange handling the PAK and executing the peg-out.
In that workflow, the customer hands over L-BTC and a destination address. The documentation’s workflow table says the user receives BTC to any Bitcoin address after the next batch.
Thorn said that was the route used here. SideSwap, he said, would let anyone show up with an address, withdraw from Liquid, and auto-forward the funds to whatever address the customer supplied. He described that as an end run around the allow list, while adding: "I don’t know why or why this was allowed."
CertiK points to rangeproof verification cache issue
CertiK attributed the inflation bug to ambiguous cache-key encoding in the rangeproof verification cache, which allowed two different validation inputs to produce the same cached entry.
Its analysis said that let an attacker prime the cache and then spend against a proof that nodes never rechecked, creating about 3,998.5 L-BTC. At the time of the exploit, CertiK valued those tokens at $318.7 million.
Liquid and SideSwap say the withdrawal system held
Liquid and SideSwap both said the withdrawal system itself remained intact.
Liquid said no key was compromised, including SideSwap’s. SideSwap said the tokens were burned against a valid authorization and that its service had no way to distinguish those coins from any other L-BTC.
The attackers have since returned 3,400 BTC and kept 598.5 BTC.

