Liquid Network Pauses After Purported ‘White-Hat’ Hackers Withdraw $320 Million in Bitcoin
This post was originally published on this site
Bitcoin sidechain Liquid Network has been paused after roughly 4,000 BTC worth about $320 million was withdrawn from the federation wallet backing its L-BTC token, in an incident that appears to have exploited a vulnerability in the network’s underlying software rather than compromised its cryptographic keys.
Liquid confirmed on Sunday that purported “white-hat hackers” had removed around 4,000 BTC from the federation’s reserves. The network subsequently disabled its bridge nodes, preventing new transactions, while exchanges were asked to suspend L-BTC deposits and withdrawals.
The withdrawal represented about 95% of the roughly 4,200 BTC held in the federation wallet before the incident. Bitcoin’s main network was not affected.

Liquid Network’s Statement on X (Source: X)
A legitimate-looking peg-out
The incident unfolded through Liquid’s normal peg-out process, making the exploit particularly significant.
SideSwap, a Liquid federation member that operates a peg-out service, said a customer sent 4,000 L-BTC to its service at approximately 14:05 UTC on September 6. The tokens were burned under a valid Peg-out Authorization Key (PAK) authorization.
About 23 minutes later, the Liquid Federation released approximately 3,996 BTC to the customer’s Bitcoin address.
Liquid said the transaction used SideSwap’s PAK but stressed that the key itself had not been compromised. SideSwap likewise said none of its systems had been breached.
Instead, the L-BTC used in the transaction appears to have been created through a vulnerability in Elements, the open-source software that underpins Liquid.
That distinction is central to the incident. The attacker did not apparently need to steal a federation key or break into SideSwap’s infrastructure. Instead, the vulnerability allowed L-BTC that should not have existed to enter the normal redemption process. Once those tokens passed the required checks, the federation paid out real BTC against them.
The federation wallet, which held more than 4,200 BTC before the transaction, was left with roughly 200 BTC afterward.
The precise technical root cause has not been publicly detailed by Blockstream or Liquid. A fix for the underlying vulnerability had already been added to the software codebase before the incident, but the issue had not been fully resolved across the network when the exploit occurred.
The hackers call themselves white hats
The party controlling the withdrawn bitcoin later left an on-chain message saying, “we are whitehats. contact us on chain.”
They left a message. (Source: memepool)
Blockstream responded through a signed Bitcoin transaction, providing an email address for contact. The two sides subsequently exchanged additional messages, including PGP-signed communications recorded on-chain.
The purported hackers offered to return most of the funds but attached a condition: Liquid must first patch the vulnerability and ensure that every node running the network is updated.
The actors also reportedly sent encrypted technical details about the vulnerability to Blockstream, according to Galaxy Digital research head Alex Thorn.
Blockstream subsequently acknowledged the hackers’ condition and worked to patch the affected infrastructure. However, the withdrawn bitcoin had not been returned at the time of publication.
The “white-hat” characterization has nevertheless been disputed.
Ledger Chief Technology Officer Charles Guillemet questioned whether the actors should be considered security researchers, arguing that taking hundreds of millions of dollars before disclosure differs substantially from conventional white-hat practice.
The debate highlights an increasingly difficult distinction in crypto security incidents: whether an actor who exploits a vulnerability, takes control of funds and later offers to return them after remediation should be treated as a security researcher or an attacker demanding conditions for restitution.
Liquid remains frozen
Liquid has kept its bridge infrastructure offline while federation members work on the vulnerability. Exchanges have also suspended, or prepared to suspend, L-BTC deposits and withdrawals.
Other assets issued on Liquid, including USDT, DePix and tokenized real-world assets, were reported to be unaffected by the incident. However, the network-wide pause has disrupted services that depend on Liquid’s ability to move assets between the sidechain and Bitcoin.
Liquid is a federated Bitcoin sidechain developed with Blockstream that is designed to enable faster, more confidential transactions and support the issuance of digital assets. BTC is locked on Bitcoin’s mainnet and represented as L-BTC on Liquid, with federation members responsible for managing the bridge between the two networks.
That architecture means the incident raises a broader question about where security risks sit in sidechain systems. In this case, the federation’s keys appear to have remained secure, yet a flaw in the software governing transaction validation was enough to put a substantial portion of the underlying reserves at risk.
For Liquid, the immediate priorities are clear: fully patch the vulnerability, update every affected node, determine whether the withdrawn bitcoin will be returned and establish that the bridge can safely reopen.
As of September 7, the funds remained outside the federation’s control, while Liquid itself remained paused. The incident is still developing, and the full technical explanation of how approximately 4,000 BTC was able to leave the reserve wallet has yet to be made public.
The post Liquid Network Pauses After Purported ‘White-Hat’ Hackers Withdraw $320 Million in Bitcoin appeared first on NFT Plazas.