Loading prices…
🩸BEARISH

Liquid Loses Nearly 4,000 BTC in Software Flaw Exploit

The incident shifts the risk question from key custody to software validation, while insurance terms decide whether customers recover coins, dollars, or less.

Almost 4,000 BTC left Liquid's reserve on Sept. 6 through a withdrawal the network approved, even though the private keys used to authorize it were not stolen. TRM Labs' reconstruction says attackers exploited a software flaw to create L-BTC without depositing matching Bitcoin, then exchanged the unbacked tokens for real coins. Bitquery later found that 3,400 BTC was returned on Sept. 7.

Why it matters

Liquid holds Bitcoin in a shared reserve while users receive L-BTC on a separate blockchain. When software accepts false information about the token supply or reserve, valid signatures can authorize an invalid withdrawal. The incident shows that key security prevents one class of attack, but it cannot stop trusted systems from approving the wrong transaction.

The financial responsibility is less clear than the technical failure. Insurance may cover a company's digital-asset losses, infrastructure exploits, or claims tied to software errors, but a policy may protect the company rather than directly guarantee every customer's balance. Coinbase, for example, says its crime insurance covers a portion of digital assets and warns that total losses can exceed recoveries.

Market impact

The reserve shortfall puts the focus on L-BTC backing, recovery terms, and who funds any gap between customer obligations and insurance proceeds. Returned coins reduce the amount still needed to restore the reserve, but the transaction record does not decide who owes customers the remainder.

Repayment terms also matter. A customer promised a fixed dollar amount may receive less Bitcoin if the asset price rises before payment. Providers need to state whether protection means replacement in coins, a dollar settlement, or only a limited recovery, and how temporary loss of access is handled.

Related tokens
$BTC

Frequently asked questions

  1. How did attackers remove Bitcoin from Liquid's reserve?

    Attackers exploited a software flaw to create L-BTC without depositing matching Bitcoin. They then exchanged the unbacked tokens for real coins from Liquid's reserve.

  2. Were Liquid's private keys stolen in the incident?

    No. The withdrawal was approved using private keys that had not been stolen, because the software accepted information that should not have qualified.

  3. How much Bitcoin was returned after the Liquid incident?

    Bitquery found that 3,400 BTC was returned on Sept. 7. Returned coins reduce the amount needed to restore the reserve.

  4. Does crypto insurance guarantee that customers recover their Bitcoin?

    No. A policy may cover a company's losses or certain claims without guaranteeing every customer's balance. Coverage limits and the policy's structure determine the recovery.

  5. Why can a dollar payout leave a customer short of Bitcoin?

    If compensation is fixed in dollars and BTC rises before payment, the payout buys fewer coins than the customer originally held. The agreement determines who bears that price risk.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 36m ago
Open original →