Liquid lost 4,000 BTC without stolen keys. That's the interesting part.
I spent most of this week digging into the Liquid incident.
The headline is ~4,000 BTC.
But the detail I keep coming back to is this:
the federation keys weren’t stolen.
SideSwap’s PAK wasn’t reported compromised either.
Yet unbacked L-BTC entered a peg-out path that ultimately resulted in real BTC leaving the federation wallet.
That makes this a much more interesting failure than “someone stole the keys.”
A multisig can answer:
Did enough authorized parties sign this?
It can’t answer:
Was the state that caused them to sign actually valid?
I went down the rabbit hole on the Elements range-proof verification cache, the 23.3.4 hardening, SideSwap’s place in the peg-out path and what is confirmed vs what researchers are still reconstructing.
But the broader question is what interests me more.
We add Lightning, federations, bridges, coordinators, LSPs, custodians and other layers because Bitcoin’s deliberately limited base layer can’t — and shouldn’t — do everything.
Every one buys functionality.
Every one also adds assumptions.
Bitcoin meanwhile just kept validating Bitcoin.
Full write-up:
Bitcoin Didn’t Break. Everything Around It Keeps Reminding Us Why Bitcoin Exists
Question for stackers: when you evaluate something built above Bitcoin, what’s the failure assumption you care about most: custody, unilateral exit, implementation bugs, operator coordination, or something else?
Write a comment