White-hat hackers drain $320 million in Bitcoin from Liquid Network sidechain
Attackers claiming to be security researchers have extracted 4,000 BTC from Liquid's federation wallet, representing 95% of its holdings. The hackers say they will return the funds once the underlying vulnerability is patched.

An unconventional theft mechanism
Self-described white-hat hackers have siphoned approximately $320 million in Bitcoin from the Liquid Network's federation wallet, according to reporting from CoinDesk. On September 6, Liquid—a Bitcoin sidechain operated by Blockstream, a blockchain infrastructure firm—disclosed via X that 4,000 BTC had been withdrawn, constituting roughly 95% of the wallet's total balance.
The attackers identified themselves as "whitehats" through a message encoded in a Bitcoin transaction and requested direct contact with Liquid's team. They pledged to restore the funds once the security flaw enabling the attack is resolved. The platform acknowledged the actors as "purported white-hat hackers" in its announcement.
Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.
On-chain message from the attackers
Liquid's security team responded with contact details and shifted further dialogue to encrypted channels. The network has halted transaction processing while federation members work to restore normal operations.
How Liquid operates
Established in 2018, Liquid functions as a federated sidechain enabling faster and more confidential Bitcoin transfers compared to the primary blockchain. Users deposit BTC on Bitcoin's main chain and receive L-BTC tokens on Liquid in exchange. The sidechain generates blocks approximately every minute, with finality achieved in roughly two minutes. Instead of relying on traditional mining, Liquid's security depends on a federation comprising more than 80 exchanges, brokers, and financial institutions. A rotating group of 15 functionaries manages block signing and custody of the multisig wallet containing pegged Bitcoin, with 11 signatures required to authorize fund movements.
The unusual nature of the exploit
The attack's mechanics diverge markedly from typical cryptocurrency thefts. In January, for instance, Step Finance, a Solana-based platform, suffered a $40 million loss when attackers compromised devices of company executives to obtain treasury wallet keys. By contrast, Liquid reported that no cryptographic keys were breached in this incident.
Instead, the coins exited through the Peg-out Authorization Key (PAK) connected to SideSwap, a decentralized exchange operating on Liquid. Liquid clarified that this key, along with all others, remained secure. SideSwap provided a parallel explanation: a customer transferred 4,000 L-BTC to its peg-out service at 14:05 UTC, the service processed the transaction normally, and the Liquid Federation subsequently paid out 3,996 BTC to the customer's Bitcoin address twenty-three minutes later. According to SideSwap, its infrastructure lacked the capability to distinguish these coins from any other L-BTC tokens.
Broader context for crypto security

This incident occurs during a challenging period for cryptocurrency infrastructure. The trading venue Drift halted deposits and withdrawals following a suspected $270 million breach in April. Throughout 2025, approximately $17 billion in Bitcoin has been stolen, predominantly through impersonation attacks and AI-powered scams.