Actors who withdrew roughly 4,000 bitcoin—worth about $320 million—from Liquid Network’s federation wallet have offered to return most of the funds. The condition is that Blockstream first patches the vulnerability that enabled the withdrawal.
The incident, which occurred on September 6, has prompted Liquid to pause bridge activity while negotiations continue on-chain.
The Drivers of This Development
Approximately 95% of the bitcoin held in Liquid’s federation wallet was moved out in peg-out transactions. The recipients left an OP_RETURN message identifying themselves as white-hat hackers and inviting contact on-chain. Subsequent messages exchanged via Bitcoin transactions and PGP signatures clarified their position: they are prepared to send most of the bitcoin back to the federation address once the underlying bug in Elements is fixed and every node is updated. Liquid and Blockstream have confirmed that the SideSwap peg-out authorization key itself was not compromised, pointing instead to a software vulnerability. Bridge nodes were disabled and exchanges were asked to suspend L-BTC deposits and withdrawals. For perspective, the remaining federation balance dropped to roughly 200 BTC, while other assets issued on Liquid, including USDT and tokenized real-world assets, were unaffected.
It is important to note the fundamental difference between a conventional theft that seeks to permanently extract value and a claimed white-hat disclosure that withholds funds pending a fix: the former prioritizes retention of the assets, while the latter ties their return to remediation of the vulnerability.
Impact and Broader Context
The episode has left Liquid’s L-BTC temporarily under-backed relative to the withdrawn reserves and has halted new peg activity. Communication between the parties remains publicly verifiable on the Bitcoin blockchain, providing unusual transparency into the negotiation. The offer to return “most” of the bitcoin leaves open the possibility of a retained bounty, a common feature in some past white-hat or negotiated returns. Confidence in federated sidechains and the security of Liquid’s peg mechanism is under immediate scrutiny.
This development sparks important discussions about the security of Bitcoin sidechains and the practical meaning of white-hat claims when large sums are moved first and disclosed afterward. Supporters of the actors’ approach argue that forcing a rapid patch by controlling the funds can accelerate remediation. Critics question the white-hat designation when hundreds of millions are withdrawn before any responsible disclosure and note the residual risk while the bug remains unpatched. Analysts observe that the on-chain dialogue itself has become a notable case study in crisis communication within the Bitcoin ecosystem.
Looking ahead, the speed of the software fix, the completeness of the node rollout, and the actual return of funds will determine how the incident is ultimately resolved. This analysis is based on Liquid Network statements, on-chain messages, and contemporaneous reporting for accuracy and reliability. The final amount returned and the status of the vulnerability remain subject to ongoing developments.
