Share this article

Blockstream's Liquid Network Sent $8M in BTC Unsafely, Says Bitcoin Developer

Bitcoins stored on the Liquid Network were temporarily able to be seized by network moderators Thursday night.

Updated Sep 14, 2021, 8:57 a.m. Published Jun 26, 2020, 4:09 p.m.
(Shutterstock)
(Shutterstock)

Bitcoins stored on the Liquid Network were temporarily able to be seized by network moderators Thursday night. The potential vulnerability in the Bitcoin sidechain's security parameters was discovered by Summa founder James Prestwich.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Liquid – a network developed and overseen by Blockstream and meant to move bitcoins around more quickly than the Bitcoin blockchain – moved 870 bitcoins that had been stuck in a queue since June 11 waiting to be processed.

Occurring Thursday at 17:19 GMT, the holders of the network's emergency two-of-three multisig wallet had potential access to the funds for about one hour, according to Prestwich. The transaction was processed normally, using the network's 11-of-15 multisig method.

“This was not a normal operation. If anyone says it is, they are wrong. It directly contradicts [Liquid’s] docs and public statements,” Prestwich said in a private message.

At current prices, the transaction is valued at roughly $8 million.

“This is a known issue caused by an inconsistency between the timelocks used by Liquid’s functionary [hardware security modules] and the functionaries themselves,” Blockstream Marketing Director Neil Woodfine told CoinDesk in a private message. “Despite the issue, the funds are always safe.”

Woodfine said that “recent growth in the Liquid Network” and coordination plans caused by the coronavirus pandemic have led to difficulty in updating firmware relating to the timelocks. Those updates should be implemented by Q4 2020, he said.

Added Prestwich:

"To be secure, these systems must operate reliably and on-spec. In this case the Liquid federation did neither. As a result, Blockstream's administrator backdoor activated, and Liquid security became dependent on trusting the company."

How Liquid works

Liquid operates as a sidechain to the Bitcoin network. It uses a one-to-one pegged token called L-BTC to move funds around more quickly than the regular network, which is overseen by a federation of select nodes.

Those nodes are typically hosted by large over-the-counter (OTC) trading desks or crypto exchanges. Each transaction, moreover, must be signed by 11 of 15 representative bodies. Liquid currently has 44 federation members such as BitMEX, Ledger and Xapo.

When bitcoin moves onto Liquid, it goes through a “peg-in” process where bitcoin is stored in a secure wallet moderated by the federation. LBTC is created and redeemed when bitcoin is deposited. The process reverses when bitcoin is withdrawn.

An emergency caveat does exist when bitcoins have not moved from a wallet for 30 days. In that case, a two-of-three multisig approval is activated in order to preserve the network. This is done to protect Liquid in the case of greater than one-third of the federated parties being severed from the Liquid Network.

According to Liquid’s technical documentation:

“If one-third or more of the network is ever unable to continue operating, the network would stall and the funds held would be locked up forever. To avoid this, all funds held by the Liquid Network are also accessible by a set of three emergency keys when the network has been non-functional for thirty consecutive days.”

Prestwich disclosed the security error publicly because the funds were never at risk of being openly stolen by a hacker, but only by those overseeing the emergency wallet. Those holders remain anonymous.

Whether or not this has happened in the past remains an open and pertinent security question, Prestwich added.

Prestwich is also currently an advisor to Keep, which recently launched a wrapped-bitcoin token known as tBTC.

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Deus X CEO Tim Grant: We aren't replacing finance; we're integrating it

Deus X CEO Tim Grant (Deus X)

The Deus X CEO discussed his journey into digital assets, the company's infrastructure-led growth strategy, and why his Consensus Hong Kong panel promises "real talk only."

What to know:

  • Tim Grant entered crypto in 2015 after early exposure to Ripple and Coinbase, drawn by blockchain’s ability to improve traditional finance rather than replace it.
  • Deus X combines investing and operating to build regulated digital finance infrastructure across payments, prime services, and institutional DeFi.
  • Grant will be speaking at Consensus Hong Kong in February.