An extraordinary security breach involving the Liquid Network resulted in roughly 4,000 bitcoin—valued at approximately $320 million—being withdrawn from the federation wallet backing L-BTC after attackers apparently exploited a software vulnerability that allowed unbacked L-BTC to enter the system and trigger what appeared to be a legitimate peg-out. The actors identified themselves as “white hats” through an on-chain message and demanded that the vulnerability be repaired before returning the funds. Liquid disabled bridge nodes and exchanges suspended L-BTC deposits and withdrawals while the flaw was investigated. The incident became considerably less financially damaging on September 7 when the attackers returned 3,400 BTC after Blockstream indicated its bridge nodes had been patched, although approximately 598.5 BTC—worth roughly $47 million—remained under the attackers’ control. The episode raises difficult questions about whether a system protected by an elaborate federation and multisignature architecture can truly be considered secure when a software-level failure can cause otherwise functioning security mechanisms to authorize an enormous withdrawal.
Key Takeaways
- Roughly 4,000 BTC worth approximately $320 million was withdrawn from Liquid’s federation wallet after an apparent Elements software vulnerability enabled the creation of unbacked L-BTC that could subsequently be processed through the normal peg-out system.
- The incident apparently did not result from the theft of federation signing keys or the compromise of SideSwap’s Peg-out Authorization Key. Instead, the transaction was treated as valid by the affected software, causing the federation’s security infrastructure to authorize a withdrawal that should never have existed.
- The self-described white-hat attackers subsequently returned 3,400 BTC after bridge nodes were patched, but retained approximately 598.5 BTC—about 15 percent of the withdrawn funds and worth roughly $47 million—leaving unresolved questions about whether the remaining bitcoin constitutes an unauthorized bounty and whether Liquid’s security model can regain users’ confidence.
In-Depth
The withdrawal of roughly $320 million in bitcoin from Liquid Network offers a particularly sobering lesson about cryptocurrency security: sophisticated safeguards are only as dependable as the software determining what those safeguards are being asked to authorize.
Liquid is a Bitcoin sidechain whose L-BTC is intended to remain backed by bitcoin held by its federation. Before the incident, its federation wallet reportedly contained more than 4,200 BTC. Roughly 4,000 BTC was subsequently withdrawn after attackers apparently obtained unbacked L-BTC through a vulnerability in Elements, the software underlying Liquid. The L-BTC was processed through SideSwap’s peg-out service, ultimately causing the federation to release approximately 3,996 BTC.
That distinction matters. Available reporting indicates that the SideSwap authorization key itself was not compromised, nor was the episode simply an attacker stealing enough private keys to overpower Liquid’s multisignature arrangement. The more troubling possibility is that the security apparatus functioned according to its design while being fed false information produced by a software flaw.
The attackers then used Bitcoin’s OP_RETURN functionality to identify themselves as white hats and communicate with those attempting to recover the funds. They demanded that the vulnerability be repaired and nodes patched before returning the bitcoin.
After Blockstream indicated that bridge nodes had been patched, 3,400 BTC was returned to the federation address. Approximately 598.5 BTC remained with the attackers.
Returning most of the money substantially reduces the immediate financial damage, but it does not erase the underlying failure. The central issue is no longer merely whether Liquid recovers its reserves. It is whether users can confidently entrust bitcoin to a federated sidechain whose technical controls permitted nearly its entire reserve to leave because a software vulnerability caused an illegitimate transaction to appear legitimate.

