Key Takeaways
- Approximately 4,000 BTC valued at $320 million was withdrawn from Liquid Network’s federation wallet by actors claiming to be ethical hackers
- The breach originated from a code vulnerability in Elements, the open-source software framework underlying Liquid, rather than compromised security keys
- The withdrawal was processed through SideSwap, an authorized trading platform, complicating early detection efforts
- The actors have been sending Bitcoin blockchain messages to Blockstream, stating they will restore the funds after the vulnerability is resolved
- No other digital assets on the platform, including USDT, were compromised
Liquid Network, a Bitcoin sidechain designed to facilitate rapid exchange settlements, has suspended all activity following the loss of approximately $320 million in Bitcoin to individuals identifying themselves as white-hat hackers.
The breach occurred on Sunday, September 7, when actors claiming ethical intentions extracted roughly 4,000 of the 4,200 Bitcoin stored in Liquid’s federation walletārepresenting approximately 95% of total reserves.
Understanding Liquid Network
Blockstream introduced Liquid Network in 2018 as a sidechain solution layered on Bitcoin’s infrastructure, enabling cryptocurrency exchanges to process settlements more rapidly than Bitcoin’s base layer permits.
The platform utilizes L-BTC tokens, which maintain a 1:1 peg with actual Bitcoin stored within a federation wallet. This federation comprises over 80 participants, including cryptocurrency exchanges, infrastructure providers, and investment management firms.
The near-complete depletion of these reserves has sparked serious concerns regarding the viability of this settlement architecture.
Technical Details of the Security Breach
Unlike the majority of cryptocurrency breaches recorded this year, this incident did not result from stolen credentials or compromised private keys.
Rather, a coding flaw within Elementsāthe open-source software powering Liquidāenabled the creation of fraudulent Bitcoin units. These fabricated funds were subsequently transferred through SideSwap, a legitimate and authorized platform operating on the network.
According to SideSwap’s statement, its Peg-out Authorization Key remained secure. The platform indicated it lacked the capability to distinguish between authentic coins and those generated by the exploit, resulting in uniform processing of all transactions.
Cybersecurity experts indicate the vulnerability exists within the node-level architecture of Liquid’s transaction processing software, separate from hardware infrastructure or key management protocols.
The perpetrators have been communicating with Blockstream through messages embedded in Bitcoin transactions. One such message stated: “Please fix the bug first. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
Alex Thorn, research director at Galaxy Digital, reported that the hackers also transmitted encrypted technical information to Blockstream designed to assist in identifying and remedying the security flaw.
As of this writing, the stolen Bitcoin remains unreturned and network operations continue to be suspended. Bridge node functionality has been disabled, while exchanges have either suspended or are in the process of suspending L-BTC deposit and withdrawal capabilities.
Liquid has verified that alternative assets hosted on the network, including USDT, DePix, and tokenized real-world assets, remain unaffected by the exploit.
This security event comes on the heels of last week’s $6 million drainage from a lending protocol associated with Crypto.com, as well as an earlier security incident involving Coldcard hardware wallet infrastructure. Liquid has yet to announce a specific timeframe for network restoration.





