Skip to main content
AVOID.NET
SideSwap1 decision on this page

Audit log

Every state-changing event for SideSwap: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-11 12:23:02Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,156,136
    sig
    5VF2TZWwsxzY…J59UoKKJexplorer ↗
    hash
    KZgRb6CQDfFf…sLrnLgivsha256 → base58
    verifying row…full verify ↗
    canonical bytes (22140 B) ▸
    {"actor":"system:backfill","investigation_id":"4da8e325-e23c-4f18-a366-4fa411bb8f02","kind":"publish","page_slug":"sideswap","published_at":"2026-09-11T12:23:01.893Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"SideSwap","sections":[{"content":"SideSwap is a non-custodial, open-source desktop and mobile application purpose-built for trading assets peer-to-peer and self-custodying assets on Blockstream's Liquid Network. The platform was founded in approximately 2020 by Scott Millar, a Swedish entrepreneur and derivatives trader who previously co-founded BlockSettle. The company is registered in Dubai, UAE. SideSwap supports Liquid Bitcoin (L-BTC), stablecoins, security tokens, and other Liquid-based assets, including Blockstream Mining Notes (BMN1/BMN2). The platform enables atomic swaps — trustless, peer-to-peer exchanges — without a central intermediary. SideSwap holds a whitelisted Peg-out Authorization Key (PAK) within the Liquid Federation, allowing users to convert L-BTC back into BTC on the Bitcoin mainchain through SideSwap's registered peg-out service. SideSwap is closely aligned with the Liquid Federation, an industry consortium organized around Blockstream's infrastructure, though it operates as an independent entity.","heading":"Background and Operations","severity":"low","sources":[{"credibility":2,"name":"SideSwap Review 2026: Swap Bitcoin and Liquid Assets — BlockDyor","type":"research","url":"https://blockdyor.com/sideswap-review/"},{"credibility":2,"name":"SideSwap: The Future of Atomic Swaps — Liquid Blog","type":"official","url":"https://blog.liquid.net/sideswap-the-future-of-atomic-swaps/"},{"credibility":2,"name":"SideSwap — Tracxn Company Profile","type":"other","url":"https://tracxn.com/d/companies/sideswap/__YIZ2W1HNQLIF0uJSNhBCaeA56epFeb9qzoXM9DqTfU4#founders-and-board-of-directors"}]},{"content":"On September 6, 2026, at approximately 14:28 UTC (Liquid block 4,050,336), the Liquid Network was drained of approximately 3,996 BTC — worth roughly $320 million at the time — through SideSwap's Peg-out Authorization Key (PAK). The attacker exploited a vulnerability in the open-source Elements software related to how Liquid nodes cached range proof verifications. Specifically, a cache-key collision in the confidential transactions verification logic allowed an actor to prime the cache with a valid rangeproof, then reuse that cached proof in a new transaction that committed to a massive positive L-BTC balance without corresponding BTC reserves — a forgery that validating nodes did not detect. The attacker reportedly made approximately 70 trial transactions to refine the exploit before executing the drain. The fabricated L-BTC was then routed to SideSwap's peg-out service, which burned the tokens through the standard authorization process and instructed the federation to release approximately 3,996 real BTC to attacker-specified addresses. The federation reserve collapsed from roughly 4,205 BTC to approximately 197–202 BTC — a loss of approximately 95% of reserves — in less than half a minute. Liquid Network confirmed that no federation private keys were compromised; the withdrawal signatures were technically valid. SideSwap stated that its PAK was not compromised and that it 'correctly processed the 4,000 L-BTC request, burned the tokens, and instructed the federation to release 3,996 BTC.' SideSwap confirmed it 'had no way to tell those coins from any other L-BTC,' as the validation failure occurred upstream of its authorization checks at the transaction level within the Elements software.","heading":"September 2026 Liquid Network Exploit: SideSwap as Exit Vector","severity":"critical","sources":[{"credibility":1,"name":"Liquid Network Incident Report, September 8, 2026 — @Liquid_BTC on X","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — Crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":1,"name":"Bitcoin Network Used by Exchanges Hit by $320 Million Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit [2026] — Shattered.io","type":"research","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"$320M Bitcoin Hack: What Really Happened to Liquid Network? — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/bitcoin/320m-bitcoin-hack-what-really-happened-to-liquid-network/"},{"credibility":2,"name":"The Liquid Network Exploit: $320M Pegged Out, Every Key Intact — DeFi Prime","type":"research","url":"https://defiprime.com/liquid-network-peg-out-exploit"}]},{"content":"In a post-mortem released on September 9, 2026, SideSwap acknowledged a set of operational oversights that contributed to the severity of the exploit, distinct from the underlying Elements software vulnerability. According to reporting on the post-mortem, SideSwap identified three key failures: (1) its PAK key was kept connected to the internet at all times with no offline or cold-storage safeguard; (2) peg-out payouts to customers were processed automatically and forwarded in the same block without human review or intervention; and (3) SideSwap ran no size, velocity, or origin checks on incoming peg-out orders — meaning a single transaction for approximately 95% of the federation's total reserve passed through without triggering any alert or manual hold. SideSwap characterized the root cause of the exploit as 'a bug in the Elements software' rather than a failure of its own key infrastructure, and noted that its PAK was not compromised. However, critics and independent analysts noted that transaction-size anomaly detection and supply-invariant verification — checking that the total L-BTC in circulation matched the BTC held in reserve — could have served as a second layer of defense independent of the upstream Elements bug. As of the time of writing, it is not publicly confirmed whether SideSwap has implemented such controls following the incident.","heading":"SideSwap Operational Failures Acknowledged","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Resumes Operations After $320M Security Breach — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/liquid-network-resumes-operations-after-320m-security-breach/"},{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Exploit Explained [2026] — Tech-Insider","type":"news_article","url":"https://tech-insider.org/liquid-network-bitcoin-hack-320-million-2026/"},{"credibility":2,"name":"The Liquid Incident: When Bitcoin Security Meets Federated Bridges — James Tsetsekas","type":"research","url":"https://blog.jamestsetsekas.com/posts/the-liquid-incident-when-bitcoin-security-meets-federated-bridges/"}]},{"content":"On September 7, 2026, at block 965,950, the actors who executed the drain returned approximately 3,400 BTC to the Liquid federation peg wallet after Blockstream deployed an emergency patch to bridge nodes. The actors communicated through Bitcoin OP_RETURN on-chain messages, identifying themselves as 'whitehats' and stating they intended to return funds after the vulnerability was fixed. The remaining approximately 598.5 BTC — valued at roughly $47 million — was not returned. The actors subsequently demanded a 10% bounty from Blockstream as a condition for returning the outstanding balance. On September 11, 2026, Blockstream publicly refused the demand, stating it would pursue every lawful avenue including cooperation with law enforcement, exchanges, forensic specialists, and other relevant parties to trace and recover the assets. Blockstream's CEO, Adam Back, stated that the 1:1 L-BTC to BTC peg would be covered by Blockstream, urging holders not to panic-sell L-BTC. The Liquid Network resumed controlled block production on September 10, 2026, though peg-in and peg-out operations remained suspended pending further validation. The characterization of the actors as 'whitehats' remains disputed: Ledger CTO Charles Guillemet publicly challenged the label, arguing that withdrawing hundreds of millions of dollars before making contact diverges sharply from standard responsible disclosure practice.","heading":"Recovery and Outstanding Funds","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Blockstream refuses ransom demand after recovering 85% of stolen BTC — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/blockstream-refuses-ransom-liquid-exploit/"},{"credibility":2,"name":"Blockstream Rejects 10% Bounty Demand on 598.5 BTC — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/11/blockstream-rejects-10-bounty-demand-says-it-will-cover-liquids-bitcoin-gap/"},{"credibility":2,"name":"Ledger CTO Challenges 'Whitehat' Claim After Liquid's 4,000 BTC Peg-Out — Blockonomi","type":"news_article","url":"https://blockonomi.com/ledger-cto-challenges-whitehat-claim-after-liquids-4000-btc-peg-out"},{"credibility":2,"name":"Liquid sidechain exploiters mint $318.7 million in L-BTC, return 3,400 BTC — Coin Turk","type":"news_article","url":"https://en.coin-turk.com/liquid-sidechain-exploiters-mint-318-7-million-in-l-btc-return-3400-btc/"}]},{"content":"The incident exposed a structural risk in how the Liquid Network's Peg-out Authorization Key system concentrates exit-path authority. The PAK system was designed as a defense against compromised federation signing keys: by requiring that peg-out destinations be derived from a whitelisted PAK entry, the system prevents a rogue functionary majority from redirecting reserves to themselves. However, the system provides no protection against a scenario in which the L-BTC being redeemed was itself not legitimately backed — the PAK validates the destination, not the legitimacy of the asset being burned. Because SideSwap is a whitelisted PAK holder and processes peg-outs as a service to end users, the attacker effectively had access to a legitimate exit channel for unbacked tokens without needing to compromise any key. Analysts noted that a supply invariant check — independently reconciling the total L-BTC in circulation against the BTC held in the federation reserve — maintained at the PAK provider level would represent a second line of defense. Whether Liquid's PAK architecture will be revised to require such checks from peg-out service providers is, as of September 2026, an open question. The incident is the largest recorded single-transaction drain of a Bitcoin sidechain reserve.","heading":"Systemic Risk: PAK as Unguarded Concentration Point","severity":"high","sources":[{"credibility":2,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — Codeant","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"},{"credibility":2,"name":"The Liquid Network Exploit: $320M Pegged Out, Every Key Intact — DeFi Prime","type":"research","url":"https://defiprime.com/liquid-network-peg-out-exploit"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"}]},{"content":"SideSwap suspended peg-in and peg-out operations immediately following the September 6, 2026 incident. As of the Liquid Network's controlled restart on September 10, 2026, peg operations remained suspended. SideSwap's instant swap services were also paused pending confirmation that transaction clearing was safe. No regulatory action against SideSwap had been publicly reported as of September 11, 2026. The platform operates without KYC requirements on its peer-to-peer swap functions. SideSwap is based in Dubai, UAE, and no formal law enforcement engagement with the company was publicly reported in connection with this incident, though Blockstream stated it would cooperate with 'exchanges, service providers, forensic specialists' in tracing the stolen funds. SideSwap's open-source GitHub repository (sideswap-io/sideswapclient) remains publicly accessible.","heading":"Service Status and Regulatory Context","severity":"medium","sources":[{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Liquid Network Pauses After $320M Bitcoin Peg-Out Drains Most Reserves — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/liquid-network-pauses-after-320m-bitcoin-peg-out-drains-most-reserves/"},{"credibility":2,"name":"SideSwap GitHub Repository — sideswap-io","type":"official","url":"https://github.com/sideswap-io/sideswapclient"}]}],"sources_used":[{"credibility":1,"name":"Liquid Network Incident Report, September 8, 2026 — @Liquid_BTC on X","type":"official","url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"credibility":1,"name":"Bitcoin Network Used by Exchanges Hit by $320 Million Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys"},{"credibility":2,"name":"Liquid Network drained of $320M in cache bug exploit — Crypto.news","type":"news_article","url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Sidechain Exploit [2026] — Shattered.io","type":"research","url":"https://shattered.io/liquid-network-320-million-hack-2026/"},{"credibility":2,"name":"$320M Bitcoin Hack: What Really Happened to Liquid Network? — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/bitcoin/320m-bitcoin-hack-what-really-happened-to-liquid-network/"},{"credibility":2,"name":"The Liquid Network Exploit: $320M Pegged Out, Every Key Intact — DeFi Prime","type":"research","url":"https://defiprime.com/liquid-network-peg-out-exploit"},{"credibility":2,"name":"Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"credibility":2,"name":"Blockstream refuses ransom demand after recovering 85% of stolen BTC — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/blockstream-refuses-ransom-liquid-exploit/"},{"credibility":2,"name":"Blockstream Rejects 10% Bounty Demand on 598.5 BTC — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/11/blockstream-rejects-10-bounty-demand-says-it-will-cover-liquids-bitcoin-gap/"},{"credibility":2,"name":"Ledger CTO Challenges 'Whitehat' Claim After Liquid's 4,000 BTC Peg-Out — Blockonomi","type":"news_article","url":"https://blockonomi.com/ledger-cto-challenges-whitehat-claim-after-liquids-4000-btc-peg-out"},{"credibility":2,"name":"Liquid Network Resumes Operations After $320M Security Breach — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/liquid-network-resumes-operations-after-320m-security-breach/"},{"credibility":2,"name":"Liquid Network Hack: $320M Bitcoin Exploit Explained [2026] — Tech-Insider","type":"news_article","url":"https://tech-insider.org/liquid-network-bitcoin-hack-320-million-2026/"},{"credibility":2,"name":"Liquid sidechain exploiters mint $318.7 million in L-BTC, return 3,400 BTC — Coin Turk","type":"news_article","url":"https://en.coin-turk.com/liquid-sidechain-exploiters-mint-318-7-million-in-l-btc-return-3400-btc/"},{"credibility":2,"name":"The Liquid Incident: When Bitcoin Security Meets Federated Bridges — James Tsetsekas","type":"research","url":"https://blog.jamestsetsekas.com/posts/the-liquid-incident-when-bitcoin-security-meets-federated-bridges/"},{"credibility":2,"name":"Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught — Codeant","type":"research","url":"https://codeant.ai/blogs/liquid-network-hack-attack-path-validation"},{"credibility":2,"name":"SideSwap Review 2026: Swap Bitcoin and Liquid Assets — BlockDyor","type":"research","url":"https://blockdyor.com/sideswap-review/"},{"credibility":2,"name":"SideSwap — Tracxn Company Profile","type":"other","url":"https://tracxn.com/d/companies/sideswap/__YIZ2W1HNQLIF0uJSNhBCaeA56epFeb9qzoXM9DqTfU4#founders-and-board-of-directors"},{"credibility":2,"name":"SideSwap GitHub Repository — sideswap-io","type":"official","url":"https://github.com/sideswap-io/sideswapclient"},{"credibility":2,"name":"Liquid Network Exploit Drained $316M Via Software Bug, Not Stolen Keys — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/326941/20260908/liquid-network-exploit-drained-316m-via-software-bug-not-stolen-keys.htm"},{"credibility":2,"name":"Liquid Network Pauses After $320M Bitcoin Peg-Out Drains Most Reserves — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/liquid-network-pauses-after-320m-bitcoin-peg-out-drains-most-reserves/"}],"summary":"SideSwap is an open-source, non-custodial peer-to-peer trading platform and wallet built on Blockstream's Liquid Network, founded in 2020 by Scott Millar. On September 6, 2026, SideSwap's Peg-out Authorization Key (PAK) was the mechanism through which approximately 3,996 real BTC — worth roughly $320 million — was released from the Liquid federation reserve in a single transaction, following an Elements software vulnerability that allowed the minting of unbacked L-BTC. SideSwap's own post-mortem acknowledged operational oversights including keeping its PAK key connected to the internet at all times and running no size, velocity, or origin checks on peg-out orders, though the underlying vulnerability originated in the open-source Elements codebase maintained by Blockstream.","timeline":[{"date":"2020-01-01","event":"SideSwap founded by Scott Millar (approximate year; exact date not publicly confirmed).","source":"BlockDyor SideSwap Review 2026","source_url":"https://blockdyor.com/sideswap-review/"},{"date":"2026-09-06","event":"At 15:53:10 UTC (Liquid block 4,050,336), a vulnerability in the Elements software cache is exploited. Approximately 4,000 unbacked L-BTC are minted via a rangeproof cache-key collision.","source":"Liquid Network Incident Report — @Liquid_BTC","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-06","event":"At approximately 14:28 UTC, 3,996 BTC exits the Liquid federation reserve in a single transaction through SideSwap's PAK, collapsing reserves from ~4,205 BTC to ~202 BTC. Liquid Network halts transaction processing.","source":"Liquid Network drained of $320M in cache bug exploit — Crypto.news","source_url":"https://crypto.news/liquid-network-320-million-drain-cache-bug-unbacked-bitcoin/"},{"date":"2026-09-07","event":"Blockstream deploys emergency patch to bridge nodes at 01:09 UTC. Attackers communicate via Bitcoin OP_RETURN messages, identifying themselves as 'whitehats' and stating they will return funds after the vulnerability is fixed.","source":"Liquid Network Incident Report — @Liquid_BTC","source_url":"https://x.com/Liquid_BTC/status/2097404704028545175"},{"date":"2026-09-07","event":"At block 965,950, 3,400 BTC is returned to the Liquid federation peg wallet by the actors. Approximately 598.5 BTC is retained.","source":"Liquid sidechain exploiters mint $318.7 million in L-BTC, return 3,400 BTC — Coin Turk","source_url":"https://en.coin-turk.com/liquid-sidechain-exploiters-mint-318-7-million-in-l-btc-return-3400-btc/"},{"date":"2026-09-08","event":"Liquid Network publishes formal incident report. Ledger CTO Charles Guillemet publicly challenges the 'whitehat' characterization, comparing the incident to prior exploits where funds were moved before communication.","source":"Ledger CTO Challenges 'Whitehat' Claim — Blockonomi","source_url":"https://blockonomi.com/ledger-cto-challenges-whitehat-claim-after-liquids-4000-btc-peg-out"},{"date":"2026-09-09","event":"SideSwap releases a post-mortem acknowledging operational oversights: PAK key kept online at all times, automatic same-block payouts with no human review, and no size, velocity, or origin checks on peg-out orders.","source":"Liquid Network Resumes Operations After $320M Security Breach — Crypto Economy","source_url":"https://crypto-economy.com/liquid-network-resumes-operations-after-320m-security-breach/"},{"date":"2026-09-10","event":"Liquid Network resumes controlled block production at 12:26 UTC. Peg-in and peg-out operations remain suspended. Adam Back states Blockstream will cover the 1:1 L-BTC to BTC peg.","source":"Liquid Network Restarts After $320M Exploit — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/10/liquid-network-restarts-after-320m-exploit-adam-back-says-lbtc-peg-will-be-covered/"},{"date":"2026-09-11","event":"Blockstream publicly refuses the actors' demand for a 10% bounty (approximately 59.85 BTC) as a condition for returning the remaining 598.5 BTC, stating it will pursue all lawful recovery avenues.","source":"Blockstream Rejects 10% Bounty Demand — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/11/blockstream-rejects-10-bounty-demand-says-it-will-cover-liquids-bitcoin-gap/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision b5f3f39b-2ead-4d29-9076-d0c87db08219
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.