Galaxy’s Alex Thorn says Liquid’s approved-address rule did not stop the bitcoin thieves

Galaxy’s Alex Thorn says Liquid’s approved-address rule did not stop the bitcoin thieves

N
News Editor
2026-09-10 12:57:03
Alex Thorn, head of firmwide research at Galaxy Digital, said Liquid’s approved-address restriction did not prevent the Sept. 6 attackers from moving bitcoin off the sidechain. According to CertiK, the incident began when a software flaw let an attacker create about 3,998.5 L-BTC that had no bitcoin backing, then convert those tokens into real BTC through Liquid’s own withdrawal process. Unchained reported that the withdrawals drained about 95% of the bitcoin pegged into Liquid before the sidechain was frozen the same day. Liquid’s developer documentation says peg-outs require a Peg-out Authorization Key, or PAK, and states that only users with registered PAK entries can withdraw to Bitcoin. Thorn said on Unchained’s Uneasy Money podcast that the restriction did not actually bind the attackers because ordinary users often rely on intermediaries such as federation members or exchanges. He pointed to a workflow described in Liquid’s documentation and said SideSwap would accept a destination address and auto-forward withdrawn BTC to that address. CertiK attributed the exploit to ambiguous cache-key encoding in the rangeproof verification cache. Liquid and SideSwap both said the withdrawal system itself remained intact, and Liquid said no key, including SideSwap’s, had been compromised. The attackers have since returned 3,400 BTC and kept 598.5 BTC.

Alex Thorn, head of firmwide research at Galaxy Digital, said Liquid’s approved-address withdrawal restriction did not stop the people behind the Sept. 6 incident from moving bitcoin out of the sidechain.

Liquid is a Bitcoin sidechain operated by a federation of exchanges and companies. Real bitcoin is held in a shared wallet and used to back the L-BTC token that circulates on the network.

Exploit led to roughly 4,000 unbacked L-BTC

According to an analysis by security firm CertiK, someone exploited a bug in Liquid’s software on Sept. 6 and created roughly 4,000 L-BTC that had no bitcoin backing. The attacker then converted those tokens into real bitcoin through Liquid’s own withdrawal system.

Unchained reported that the withdrawal drained about 95% of the bitcoin pegged into Liquid, and the sidechain was frozen the same day.

Liquid said the parties responsible describe themselves as white-hat hackers.

Liquid documentation says peg-outs require registered PAK entries

Liquid does not allow just anyone to move bitcoin off the sidechain. To exit, a user returns L-BTC and the federation releases the matching BTC on the Bitcoin network, a process Liquid calls a peg-out.

The network’s developer documentation says a peg-out requires a Peg-out Authorization Key, or PAK, and states that only users with registered PAK entries can peg out. The stated purpose is to make sure that even if federation operators were compromised, user funds could not be redirected to attacker-controlled addresses.

Even so, the coins ended up at an address controlled by the people who took them.

Thorn says the restriction never actually bound them

Speaking on Unchained’s Uneasy Money podcast, Thorn said the restriction never actually applied in a way that stopped the attackers.

Liquid’s documentation says most users cannot complete that swap on their own and that the general public typically goes through a federation member or an exchange. It names SideSwap and Bitfinex as examples, with the exchange handling the PAK and executing the peg-out.

In that workflow, the customer hands over L-BTC and a destination address. The documentation’s workflow table says the user receives BTC to any Bitcoin address after the next batch.

Thorn said that was the route used here. SideSwap, he said, would let anyone show up with an address, withdraw from Liquid, and auto-forward the funds to whatever address the customer supplied. He described that as an end run around the allow list, while adding: "I don’t know why or why this was allowed."

CertiK points to rangeproof verification cache issue

CertiK attributed the inflation bug to ambiguous cache-key encoding in the rangeproof verification cache, which allowed two different validation inputs to produce the same cached entry.

Its analysis said that let an attacker prime the cache and then spend against a proof that nodes never rechecked, creating about 3,998.5 L-BTC. At the time of the exploit, CertiK valued those tokens at $318.7 million.

Liquid and SideSwap say the withdrawal system held

Liquid and SideSwap both said the withdrawal system itself remained intact.

Liquid said no key was compromised, including SideSwap’s. SideSwap said the tokens were burned against a valid authorization and that its service had no way to distinguish those coins from any other L-BTC.

The attackers have since returned 3,400 BTC and kept 598.5 BTC.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.