Liquid Network: 4,000 BTC ($320M) Drained in Self-Claimed White-Hat Hack

Share

Liquid Network, the Bitcoin sidechain operated by Blockstream, suspended all transactions after approximately 4,000 BTC (~$320 million) were withdrawn by actors claiming to be white-hat hackers. Blockstream is now attempting to reach the attackers via a signed on-chain message, while bridge nodes remain offline.

🔑 Key takeaways

  • ~4,000 BTC (~$320M) withdrawn from the Liquid Federation wallet.
  • The amount represents ~95% of the sidechain’s BTC reserves.
  • The exploit leveraged a software bug in Elements, with no private key compromise.
  • Bridge nodes are offline, but Bitcoin mainnet transactions remain functional.

A massive withdrawal claimed by white-hats

On September 6, 2026, Liquid Network announced on X the suspension of its transactions after the withdrawal of approximately 4,000 bitcoins, valued at roughly $320 million at the time. The perpetrators left an on-chain message reading « We are whitehats. contact us on chain », a classic modus operandi for ethical hackers who move funds to safety before negotiating their return.

According to the Mempool tracker, the amount represents nearly 95% of the network’s bitcoin reserves — a striking share of assets managed by the Liquid Federation. Blockstream, which has developed and maintained the sidechain since its launch in 2018, clarified that the funds transited through SideSwap, an exchange platform native to the Liquid ecosystem.

In its official statement, Blockstream said it was « contacting the alleged white-hats on-chain with a signed message », while stressing that no private key and no other cryptographic component was compromised during the operation.

A software bug in Elements, not a cryptographic compromise

The technical analysis reveals that the operation was made possible by a bug in the Elements software, the open-source engine on which Liquid Network is built. Blockstream stressed that no private key nor any other cryptographic component was compromised — a nuance that sets this incident apart from the majority of recent hacks, where attackers typically obtain keys through phishing, theft, or infrastructure compromise.

More specifically, the flaw created part of the concerned bitcoins in a distinct environment, without clearly distinguishing coins issued from the bug from those actually deposited by users. The withdrawal was carried out using the Peg-out Authorization Key (PAK), a legitimate protocol mechanism that releases BTC after a peg-in (a transfer from the main chain to the sidechain).

This distinction is crucial: most cryptocurrency hacks involve the compromise of private keys, whereas this attack exploits a bug in the protocol code itself.

Reactions and immediate market impact

Blockstream released a statement confirming that the team was attempting to reach the white-hats via a signed message and that Federation members were working on restoring service. Centralized exchanges, meanwhile, suspended LBTC deposits as a precaution. Other assets issued on Liquid, such as USDT, DePix, and tokenized real-world assets, were not affected by the incident.

« Everyone is actively working to resolve this issue and we will share information as the situation evolves. As a Liquid wallet, the Liquid functionality in Aqua is impacted, but Bitcoin transactions will work normally. »

Samson Mow, CEO of JAN3

At the time of publication, bitcoin (BTC) was trading at approximately $80,092, up just +0.24% over 24 hours. Despite the magnitude of the amount, the BTC market showed only a marginal move — a sign of relative confidence in the isolated nature of the incident and in Blockstream’s reputation as the operator.

A deteriorating security context for the crypto ecosystem

The episode is part of a string of troubling incidents for the crypto ecosystem, marked by several high-profile security breaches in recent weeks:

EventAmount / ScopeIncident Type
Liquid Network (Sept 2026)~4,000 BTC (~$320M)Software bug (Elements)
Coldcard (Aug 2026)~$88M in BTCHardware wallet hack
SafePal (Aug 2026)~40,000 customers exposedData breach
Crypto.com lending~$6MSuspicious withdrawal

The limits of the centralized-reserve sidechain model

Liquid Network relies on a two-way peg mechanism that issues Liquid Bitcoin (L-BTC) in proportion to the BTC deposited in reserve. This architecture, designed to speed up transfers between exchanges, brokers, and institutional players, nonetheless concentrates custody of the underlying bitcoins with a federation of trusted actors.

The incident raises a fundamental question: can a single software bug allow nearly all reserves to be drained? Security experts note that the vulnerability lies at the level of Liquid’s transaction nodes, not in a compromise of keys or hardware modules — an important distinction at a time when most crypto hacks rely on private key compromise.


Conclusion: toward a rethink of federated custody models?

Liquid Network has, at this stage, communicated no precise timeline for the resumption of the network or for the return of funds. If the authors truly are white-hats, full recovery of the 4,000 BTC remains uncertain and will depend on Blockstream’s ability to negotiate with them. Conversely, if coordination fails, the funds could remain locked indefinitely at the receiving address.

Beyond the Liquid incident, the episode underscores the need for independent and regular security audits for centralized-reserve protocols, as Layer 2 solutions gain importance on Bitcoin. For investors and users, it also highlights the importance of not confusing settlement speed with the security of the underlying reserve.

Sources

This article is for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles