The Shared Code Trap: 4,000 Bitcoin Drained From Liquid as Multisig Agrees With a Flaw
Fifteen independent signers, zero stolen keys — and eleven honest machines approving a bug that emptied the sidechain.
The security model was supposed to be bulletproof: fifteen geographically distributed companies guarding independent cryptographic keys, requiring eleven concurrent signatures before funds could peg out from Liquid to mainchain Bitcoin. Yet when an exploit struck on Wednesday, eleven legitimate signers dutifully approved a withdrawal that drained nearly every satoshi in reserve.
Ungovernable reported the scale of the collapse: Roughly 4,000 Bitcoin was withdrawn from Liquid after a software bug allowed LBTC that should never have existed to be accepted as valid.
Over $320 million in value crossed the bridge, leaving barely 150 to 200 Bitcoin on the entire sidechain before block generation halted.
The failure tore through assumptions about threshold security. As Ungovernable observed, Every signer was reading the same faulty software, so every signer agreed. The number of keys does not fix a shared code failure.
Obi crystallized the broader lesson: The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money.
Dispatched from commentary by Ungovernable, Ungovernable on the federation, and Obi.