Hackers Drain $320M in Bitcoin from Liquid Network, Claiming White-Hat Intent
Approximately $320 million in Bitcoin was drained from the Liquid Network's federation wallet by attackers claiming to be white-hat hackers seeking to fix a vulnerability.

Hackers have successfully drained an estimated $320 million in Bitcoin from the federation wallet that backs the Liquid Network, a Bitcoin sidechain developed by Blockstream. The attackers, who claim to be "white-hats," withdrew nearly 95 percent of the wallet's holdings, amounting to approximately 4,000 BTC out of the roughly 4,200 BTC it contained.
In response to the incident, Liquid announced it had disabled its bridge nodes while federation members investigate the breach. The network also urged exchanges to suspend deposits and withdrawals of its wrapped Bitcoin (L-BTC) to prevent further complications. The attackers, in a message embedded within a Bitcoin transaction, identified themselves as white-hat hackers and requested that Blockstream address a vulnerability they claimed put the chain at risk.
"Please fix the bug first," the on-chain message stated. "The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." Blockstream acknowledged the message and provided contact details for its security team, with communications reportedly moving to encrypted channels.
The exact method by which the attackers bypassed the wallet's security remains under investigation. Liquid indicated that the Bitcoin was withdrawn using its Peg-out Authorization Key (PAK) via SideSwap. However, the network stated that neither SideSwap's key nor any other PAK appeared to have been compromised. This raises significant questions about how such a large sum could be moved without the proper authorization keys being compromised, suggesting a potential flaw in the sidechain's security model or its authorization mechanisms.
While other assets issued on the Liquid Network, such as stablecoins, do not appear to have been directly affected, and the Bitcoin network itself remains untouched, the incident highlights the inherent risks associated with sidechain technologies. Unlike Bitcoin's decentralized security model, Liquid relies on a federation of members to collectively manage and secure the Bitcoin backing L-BTC.
The attackers have stated their intention to return "most" of the stolen Bitcoin once the identified vulnerability is fixed and Liquid's nodes are updated. The outcome of this situation, and whether all the funds are indeed returned, will likely shape the perception of this event and the attackers' claimed motives.
This incident serves as a stark reminder that sidechains, while offering additional functionalities, do not inherit the same robust security guarantees as the Bitcoin mainnet. The security of federated systems is inherently dependent on the integrity and security practices of its members and the underlying authorization protocols.