← BACK TO FEED
BitcoinLiquid Networkcrypto securityBlockstreamwhite-hat hacking

Someone Just Walked Off With 95% of Liquid Network's Bitcoin and Wants a Pat on the Back

Hackers drained approximately 4,000 BTC ($320 million) from the Liquid Network's federation wallet, representing around 95% of its holdings, while claiming to be white-hat security researchers. The individuals communicated via on-chain messages, asking Blockstream to contact them and promising to return "most" of the Bitcoin once the underlying vulnerability is patched. The exact method used to drain the wallet remains under investigation, as no Peg-out Authorization Keys appear to have been compromised.

Around $320 million worth of Bitcoin has been pulled out of the Liquid Network's federation wallet by a group claiming they did it for everyone's benefit. Whether you find that reassuring probably depends on how much Bitcoin you had sitting there.

Liquid, a Bitcoin sidechain built by Blockstream and used primarily by exchanges and trading firms, confirmed on Sunday that approximately 4,000 BTC had been drained from its federation wallet. The attacker or attackers left behind only a sliver of the original 4,200 BTC balance. Blockstream described the culprits as 'purported white-hat hackers,' which is doing some heavy lifting as corporate understatement goes.

The people responsible seem eager to frame this as responsible disclosure with extra steps. They embedded a message in a Bitcoin transaction identifying themselves as whitehats and instructing Blockstream to patch the vulnerability before they'd hand anything back. Blockstream replied on-chain with its security team's contact details, and both sides have since taken the conversation to encrypted channels. The hackers say they'll return 'most' of the Bitcoin once the bug is fixed and nodes are updated.

'Most' is doing a lot of work in that sentence.

Liquid has shut down its bridge nodes while the federation investigates, and exchanges have been asked to pause L-BTC deposits and withdrawals in the meantime. Other assets on the network, including stablecoins, appear unaffected. Bitcoin itself is obviously fine.

The mechanics of the exploit remain opaque. Liquid says the withdrawal went through SideSwap using a Peg-out Authorization Key, the mechanism that lets federation members confirm destinations are authorised to receive Bitcoin from the wallet. The strange part is that neither SideSwap's key nor any other PAK appears to have been compromised. How an apparently legitimate peg-out request managed to drain nearly the entire wallet without a key being touched is precisely what investigators are trying to work out.

This is also a timely reminder that wrapping Bitcoin inside a federated sidechain is not the same thing as Bitcoin security. Liquid's backing funds are controlled collectively by federation members, not by Bitcoin's proof-of-work. That's a fundamentally different trust model, and this incident underscores the gap.

For now the funds are with people who claim good intentions. Whether all 4,000 BTC makes it back will say rather a lot about how seriously that claim should be taken.

WATCH THE SHORT
READ NEXT
Liquid Network Hackers Return Most of the $320M Bitcoin They Nicked, Hold Rest as LeverageLiquid Hackers Give Back Most of the Bitcoin, Keep $47M as Apparent 'Fee'Trezor Customers Hit by Phishing Wave After Marketing Platform Botches SSO Security