Alex Thorn: Liquid Network Rules Failed to Stop Bitcoin Exploit
Galaxy Digital researcher Alex Thorn explains how attackers bypassed security controls during the recent Liquid sidechain exploit.

BTCcoinbeat.news
BTC/USD live chart
LIVESecurity flaws on the Bitcoin sidechain Liquid recently allowed hackers to mint thousands of unbacked L BTC tokens before draining real bitcoin from the network. The incident drained roughly 95 percent of the bitcoin pegged into the sidechain. Liquid officials quickly froze the network after the attack occurred on September 6.
While Liquid features strict withdrawal rules designed to prevent unauthorized transfers, Galaxy Digital research head Alex Thorn pointed out that these controls did not stop the funds from leaving. Thorn noted that certain exchange services on the network let users supply any destination address for withdrawals, effectively bypassing the approved address list.
Security firm CertiK traced the root cause to a cache key encoding bug that allowed validation inputs to trick node checks. The attackers created nearly 4,000 unbacked L BTC tokens worth hundreds of millions of dollars before converting them into real bitcoin. Reports indicate that the parties responsible have since returned a large portion of the stolen funds.
Traders should monitor how sidechains and layer two solutions handle software updates and validation checks moving forward. As the crypto industry builds complex scaling tools, security audits and proper testing remain vital for protecting user funds.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



