Tag: Blockstream

  • L-BTC Resumes Trading With Reserves Covering Just 85% of Supply

    L-BTC Resumes Trading With Reserves Covering Just 85% of Supply

    SideSwap Reopens Liquid Markets While Bitcoin Peg Remains Suspended

    SideSwap has reopened trading on the Liquid network even as the bridge back to Bitcoin stays closed, creating a market price for Liquid Bitcoin (L‑$BTC) before holders can redeem it for actual BTC.

    Reserve Data Shows 85% Coverage and a 627 BTC Gap

    At 22:55 UTC on Sept. 10, a Blockstream explorer endpoint recorded 4,229 L‑$BTC outstanding. A simultaneous reading of the federation reserve address showed 3,601 BTC. Those figures imply reserve coverage of roughly 85.15% and a shortfall of about 627 BTC at that moment.

    SideSwap’s own Sept. 10 statement cited an earlier snapshot of 4,205 L‑$BTC and 3,597 BTC in reserve. The later API readings used here are slightly higher on both sides, while the coverage ratio remains near 85%. Each row represents a separate time‑stamped view, making the reserve ratio a live measure rather than a settled loss estimate.

    Trading Venue and Federation Operate Under Separate Mandates

    SideSwap runs the trading venue and wallet. The Liquid Federation controls the Bitcoin reserve and authorizes the peg‑out process, while Blockstream provides core technology and publishes network status. Their distinct roles explain how venue trading can resume ahead of federation redemption.

    SideSwap describes its swap venue as a central‑limit‑order‑book market with L‑$BTC as the base asset and registered Liquid assets as quotes. Its documentation does not identify a direct L‑$BTC/BTC order book. At publication time, no reproducible post‑restart L‑$BTC/BTC price, bid‑ask spread, depth, slippage measure, or cross‑venue comparison was publicly available. The evidence confirms the reopening of SideSwap’s venue, while leaving the actual post‑restart discount or premium unmeasured.

    Price Parity Is Now a Confidence Signal, Not Proof of Backing

    Before the incident, redemption arbitrage kept the two assets aligned: a trader could buy discounted L‑$BTC, redeem it for BTC, and repeat until the discount narrowed. Suspended federation peg‑outs remove that enforcement route, so price parity becomes a confidence signal rather than proof of backing.

    A near‑par L‑$BTC price would indicate that participating buyers expect most value to be recoverable. Expectations of recapitalization could support that price. A thin order book could do the same for small orders while offering much worse execution for larger positions.

    Reserve Gap Traces Back to Sept. 6 Incident

    The reserve gap followed the Sept. 6 incident. A transaction shows 3,400 BTC returning on Sept. 7, matching earlier recovery coverage. A 22:55 UTC reading showed about 598.50048115 BTC at the address identified through that history. Supply and reserve balances can change separately, so that address balance and the later reserve gap are related evidence rather than interchangeable totals.

    Liquid Restart Proceeds in Stages

    An official Blockstream status update described the restart’s first phase. As of 10:00 UTC on Sept. 10, block production had resumed in a controlled mode without transactions. Required functionary and bridge‑node updates had been deployed, while peg operations—including PAK‑authorized peg‑outs—remained suspended during reserve restoration.

    By 22:55 UTC, the Liquid explorer’s block‑tip endpoint had reached height 4,051,868, confirming continuing block production at the snapshot time. Transaction availability still depended on the separately published operating status.

    Liquid’s homepage later said issued‑asset transfers had resumed while L‑$BTC transfers and peg‑outs remained paused. SideSwap, meanwhile, said its swaps and all markets were open. The two statements address different surfaces and leave the precise scope of L‑$BTC market settlement less clear than SideSwap’s headline alone suggests.

    This distinction also applies to transactions caught in the pause. SideSwap said peg‑ins and peg‑outs already in progress through its service would be completed after blocks resumed. It also said Bitcoin payouts completed before the pause were final. The statement covers SideSwap’s service and offers no federation‑wide guarantee for transactions initiated through other providers.

    Other issued assets have separate backing arrangements. SideSwap noted that assets such as USDt and DePix depend on their issuers rather than the L‑$BTC reserve. Their ability to move or trade therefore gives holders limited information about the condition of the Bitcoin peg.

    Restoring the Peg Requires Reserves and a Working Bridge

    Liquid’s protocol documentation defines one L‑$BTC as a claim backed by one BTC held by the federation. The peg‑out process burns L‑$BTC, validates an authorized Bitcoin destination, and releases BTC from the federation reserve.

    Direct peg‑outs require a registered Peg‑out Authorization Key. General users usually depend on a federation participant, exchange, or peg‑out partner. A dependable exit therefore requires sufficient reserve BTC and functioning authorized infrastructure through which holders can reach it.

    The Elements project released version 23.3.4, including a change that hardens proof‑cache keys. Blockstream said required functionary and bridge‑node updates had been deployed. Completion of a full independent review of the network and peg process remained undisclosed in the reviewed official updates.

    Reserve restoration is the other condition. SideSwap said Blockstream CEO Adam Back had stated that the L‑$BTC‑to‑BTC peg would receive one‑for‑one coverage. SideSwap added that it lacked insight into the method or timing. Blockstream’s status page described restoration as in progress without naming a capital source or deadline.

    Clear operating conditions form the final piece. Holders need a federation announcement that peg‑outs have resumed, an explanation of any limits or staged access, and confirmation from the provider handling their redemption route. SideSwap separately promised to explain changes to its own peg service before reopening it.

    Until those conditions are met, L‑$BTC’s market price measures confidence in the recovery process. The reserve data and disabled peg‑outs determine whether holders can actually leave Liquid with Bitcoin at par.

  • Liquid Hackers Call Blockstream ‘Delusional, Greedy, and Arrogant,’ Demand 10% Bounty

    Liquid Hackers Call Blockstream ‘Delusional, Greedy, and Arrogant,’ Demand 10% Bounty

    Blockstream-Hacker Dispute Escalates Over Liquid Sidechain Security Breach

    The conflict between Blockstream and the party claiming to be a white-hat hacker has intensified, according to a recent update from Samson Mow. The hacker has leveled serious accusations against Blockstream, alleging the company dedicated only $1.5 million—or possibly nothing—to secure approximately $5 billion in assets on the Liquid sidechain.

    Hacker Demands Bounty, Threatens Further Losses

    In a message characterized by harsh language, the hacker labeled Blockstream’s approach a “flagrant neglect of security.” The group demanded that Blockstream pay a 10% bug bounty from its own funds and warned that refusal could lead to a 15% loss for Liquid users. The communication further accused Blockstream of being “delusional, greedy, and arrogant” in its security management. The hackers also stated they intend to publish the private key required to decrypt their conversations with the company.

    Meanwhile, the Liquid sidechain remains paused. Blockstream and Federation members are working on additional security fixes, resolving a chain split, and preparing for a coordinated network restart. Users have been advised not to send Bitcoin to Liquid peg-in addresses until the network is fully operational again.

    Background: $320 Million Withdrawal and Partial Return

    The latest exchange follows the withdrawal of roughly 4,000 BTC (valued at approximately $320 million at the time) from Liquid’s Federation wallet on September 6. The party responsible initially identified as white-hat hackers, stating the funds would be returned once Blockstream addressed the security vulnerability and patched all affected nodes. After Blockstream confirmed the bridge nodes had been patched, 3,400 BTC was returned to the Federation wallet, leaving approximately 598 BTC still in the hackers’ possession.

    Mow Warns of Serious Consequences

    In a separate post on X, former Blockstream Chief Strategy Officer Samson Mow cautioned the hackers that they may be underestimating the repercussions of their actions. He noted that Blockstream’s decision to engage with them via PGP encryption was a “courtesy” and questioned whether publicly admitting to taking the BTC and then demanding a bounty was a “wise move.”

    Mow further suggested the group left behind more forensic clues than they realize and warned that returning the funds does not guarantee they can simply walk away from the incident.

    “As a white hat, the road only widens; as a black hat, you’re forever on edge. Dreaming of walking away with assets unscathed is nothing but delusion. Some doors, once opened, can never be closed again.”

  • Core Lightning Urges Upgrade After AI Reports Reveal Security Flaws

    Core Lightning Urges Upgrade After AI Reports Reveal Security Flaws

    Core Lightning has urged Lightning Network node operators to upgrade to version 26.06.7 after developers identified several security vulnerabilities in the software.

    The emergency release, issued Aug. 28, addresses issues uncovered during a 10-day security review that included reports generated with the help of artificial intelligence. Developers verified several findings and released fixes while withholding technical details under a two-week disclosure embargo.

    Maintained by Blockstream, Core Lightning is used by operators running Lightning Network nodes. Developers have not disclosed the full nature of the vulnerabilities, leaving their potential impact unclear.

    Lightning Network Operators Face Security Deadline

    The disclosure embargo gives operators time to install the fixes before researchers publish additional details in mid-September. Unpatched nodes could face increased risk once the vulnerabilities become public.

    Core Lightning recommends using signed binaries when installing version 26.06.7. Operators who cannot upgrade immediately can use the –offline flag to monitor their nodes until the update is complete.

    Older Core Lightning Versions Lose Security Support

    Versions 26.04 and older no longer receive security fixes. The latest release follows Core Lightning version 26.06.6, which was published July 22.

    Earlier this year, developers fixed denial-of-service flaws affecting versions 26.04 and 26.06rc2. The latest findings add to scrutiny of Lightning Network security as automated tools make it easier to identify weaknesses in widely used software.

    Source: cryptonews.net