Liquid Network reported that approximately 4,000 BTC—nearly all of the 4,200 Bitcoin in its federation wallet and valued at about $320 million—was withdrawn from the reserves backing its Bitcoin sidechain. The parties responsible identified themselves on-chain as white-hat hackers, alleged an undisclosed vulnerability in the current code, and said they would return “most” of the funds once every node had been patched.
The withdrawal reportedly used SideSwap and a Peg-out Authorization Key (PAK), although Liquid said neither SideSwap’s PAK nor another PAK appeared compromised and that its federation cryptographic key was not breached. Liquid disabled bridge nodes and halted new sidechain transactions while federation members investigated and restored operations; partner exchanges were asked to suspend L-BTC deposits and withdrawals. Liquid-issued stablecoins and other assets were not directly affected, and Bitcoin’s mainnet was unaffected.

Track how attackers are adapting to this technology.
11 events from the most recent confirmed update back to the earliest known activity.
Blockstream said it would not pay a ransom for the BTC taken in the Liquid exploit, rejecting the actors’ white-hat characterization and calling the continued withholding of funds theft. It said it would work with law enforcement, exchanges, service providers, and forensic specialists to trace the assets and identify those responsible if the funds were not returned.
Analysis cited by TRM Labs indicated that a flaw in Elements' cached verification of confidential-transaction range proofs allowed invalid outputs to be accepted as previously verified. Attackers reportedly used matching proof data in dozens of transactions, then minted about 4,000 unbacked L-BTC in Liquid block 4,050,336 before redeeming it from the federation reserve.
Liquid and SideSwap stated that the SideSwap Peg-out Authorization Key and no other keys were compromised. SideSwap said it processed a 4,000 L-BTC peg-out as a normal order at 14:05 UTC, and the Liquid Federation sent 3,996 BTC to the designated Bitcoin address 23 minutes later.
After its investigation and suspension, Liquid reportedly restored its peg and resumed sidechain transactions. The network reportedly added more manual review and anomaly detection for withdrawal approvals, while SideSwap's role in the withdrawal pipeline was restructured.
While the network remained paused, Blockstream and Liquid Federation members worked to resolve a chain split alongside further fixes and security improvements before safely restarting Liquid.
Former Blockstream executive Samson Mow stated that Blockstream fixed the bug allegedly used in the theft. After the fix, the purported white-hat attacker reportedly returned approximately 3,400 of the roughly 4,000 stolen BTC, while about 600 BTC remained under the attacker's control and Liquid operations stayed paused pending further improvements.
SideSwap reportedly said the unauthorized peg-out was enabled by a bug in Elements, Liquid's underlying software, which created the L-BTC used for the withdrawal. It maintained that neither its systems nor its Peg-out Authorization Key had been compromised; public technical details of the flaw were not disclosed.
Liquid Network disabled bridge nodes and paused new sidechain transactions while federation members investigated and worked to restore operations. It notified partner exchanges, which suspended L-BTC deposits; Liquid also requested that deposits and withdrawals be paused.
Blockstream posted its security team's contact details in an on-chain response, after which communications with the self-described white hats moved to encrypted channels.
The parties responsible embedded an on-chain message identifying themselves as white-hat hackers, claiming a vulnerability in the current code put the chain at risk. They said they would return most of the Bitcoin after every node was patched.
Attackers withdrew approximately 4,000 of the roughly 4,200 BTC held in Liquid Network's federation wallet, a loss valued at about $320 million. The funds were reportedly withdrawn through SideSwap using a Peg-out Authorization Key mechanism.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
18 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourceslowmist.medium.com
Open sourcechainalysis.com
Open sourcesecurityaffairs.com
Open sourcemalware.news
Open sourcetheregister.com
Open sourceteiss.co.uk
Open sourcecoindesk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.