Skip to content

Product1 publisher3 min readPublished

A node bug made Liquid's 11-of-15 multisig pay out on coins that never existed

Blockstream's federation signers behaved correctly and still released roughly 4,000 bitcoin, because the software that decides what counts as a real L-BTC is a different system from the keys guarding the peg.

The Product Desk · Product desk

Illustration accompanying A node bug made Liquid's 11-of-15 multisig pay out on coins that never existed

What happened

  • A bug in Liquid's Elements node software let an attacker mint unbacked L-BTC on Sunday and cash it out through SideSwap for roughly 4,000 bitcoin, worth about $320 million at the time.
  • Blockstream's federation keys were never stolen: vulnerable nodes read the forged coins as valid, and the signers released real bitcoin from the 11-of-15 multisig that backs the sidechain.
  • After bridge nodes were patched, the attackers sent 3,400 bitcoin back to the federation and kept 598.5, around $47 million, from the transaction that had emptied nearly all the reserves.
  • Switching from PGP notes to plaintext, the attackers demanded Blockstream pay a 10% bounty out of company money, claiming it had allocated only $1.5M to secure $5B in assets.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint A signer count describes half of a peg's security at best. Diligence that stops at key distribution cannot see the failure that actually moved the coins here, which pushes the question onto node software nobody was asked to name.
  • exposure The 3,400 bitcoin came back because the attackers chose to send it, so holders' downside was bounded by a negotiation rather than by any control the federation held.
  • precedent Paying from company funds would price a bridge bug found by exploiting it above one reported quietly, which is the incentive Guillemet says is a net negative for the ecosystem.
  • decision Anyone holding a bridged asset now has to decide whether a reserve gap settled by on-chain bargaining is a risk they can describe to their own finance committee.

Somebody put funds into L-BTC on the strength of one defensible sentence: the peg is held by a named federation behind an 11-of-15 multisig [2]. That sentence stayed true through the whole weekend, and the reserves left anyway [3][4].

A peg does two separate jobs. One is deciding which L-BTC are real, and that is the Elements node software's job. The other is authorising the release of real bitcoin against them, and that is the signers' job. The bug sat in the first job, and the second job then worked exactly as designed on top of a wrong answer: vulnerable nodes treated freshly minted, unbacked L-BTC as valid, and the federation's signers released bitcoin from the multisig [1][3]. Key distribution is the part that gets published. Validation correctness is the part that actually gated the withdrawal.

The negotiation numbers are worth doing by hand. Roughly 4,000 bitcoin described as about $320 million implies a price near $80,000 each [14], and the 598.5 bitcoin the attackers kept comes to about $47.9 million at that price, which lines up with the roughly $47 million reported [6]. The threat to cost holders 15% is their own balance divided by the take: 598.5 of 4,000 is 14.96% [15]. A 10% payout on the same base is 400 bitcoin, so honouring their own demand would mean sending back about 198.5 and keeping the rest [16]. Gizmodo reads the gap between the two figures the same way, as an implied willingness to return more while leaving the remainder as an effective bounty [10].

What brought most of it back was the attackers' decision to send it, after bridge nodes were patched [6]. Roughly 600 bitcoin of the original take is still outstanding [17], and the channel for it is a PGP conversation stuffed into Bitcoin transactions, which the attackers have now switched to plaintext while Blockstream keeps answering in signed encrypted notes [7][9]. Ledger CTO Charles Guillemet called that straight extortion and said an honest finder would have gone to Blockstream's security team, leaving the company to pause Liquid, fix the bug and pay a bounty [12]. Spiral's Greg Sanders was shorter: "Robbing a fancy bank, trying to keep a double digit percentage and accusing others of greed" [11]. Bitcoin Magazine's Shinobi argued the attackers had boxed themselves in, since returning everything would almost certainly have earned a sizable bounty in the legal clear [13].

The grid worth carrying into your own review has two axes: whether the keys are honest, and whether the validating software agrees with reality. Custody arrangements, federated bridges and reserve attestations are all marketed along the first axis. This incident sits in the quadrant where the keys are honest and the validation is broken, which is a quadrant no signer count can describe. The forcing function is a two-line note for each bridged asset a team holds: the signer arrangement you would cite on Friday, and the name and version of the software those signers depend on to tell them a deposit is real. The first line comes off a website. The second usually takes an email to the vendor, and how long that email takes to answer tells you what you are actually trusting.

What to watch

  • Whether Blockstream pays any part of the 10% demand, and whether the roughly 600 outstanding bitcoin reaches the federation address.
  • Whether the attackers publish the private key they promised, opening the full negotiation record to outside reading.
  • Whether Blockstream names the Elements defect and the node versions that accepted the unbacked L-BTC.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories