TLDR
Hackers drained about 4,000 Bitcoin from the Liquid sidechains federation wallet and now say they will return most of it after a software bug is fixed.
- Purported white-hat attackers exploited a flaw on Blockstreams Liquid Network and withdrew roughly 4,000 BTC, worth about 320 million dollars, from its federation wallet.
- Liquid has paused its bridge, L-BTC is massively undercollateralized, and users cannot currently move assets, but the Bitcoin main chain itself is not compromised.
- The hackers pledge to return most funds after patches, yet skepticism remains, and the eventual treatment of L-BTC holders and peg losses is still unclear.
Deep Dive
1. What Actually Happened
Liquid Network, a Bitcoin (BTC) sidechain run with Blockstream tech, halted operations after actors claiming to be white-hat hackers withdrew about 4,000 BTC from its federation wallet, around 320 million dollars at current prices. Reports from outlets such as Cointelegraph and The Block describe Liquid disabling bridge nodes and exchanges suspending L-BTC deposits and withdrawals after the incident.
According to multiple analyses, the withdrawal used SideSwaps Peg-out Authorization Key (PAK), but the key itself was not compromised; instead, the attackers exploited a bug in Elements, the open source software that underpins Liquid, to create invalid L-BTC that the federation treated as real. The attackers wrote on chain that they are whitehats and have told Blockstream they will return most of the BTC once the bug is fixed and all nodes are patched, as summarized by Cryptopotato and The Block.
This was a bridge/sidechain infrastructure failure, not a hack of Bitcoins base protocol or its consensus rules.
2. Impact On Users And L-BTC
Because roughly 4,000 of about 4,200 BTC backing L-BTC were drained, coverage of L-BTC has cratered to a single digit percentage of what is needed for a one to one peg, as noted by Bitcoin.com. In simple terms, there are far more L-BTC tokens than real BTC now sitting in the federation wallet.
Liquid has paused bridge nodes, exchanges have frozen L-BTC flows, and services built on Liquid (for example, Aquas Liquid functionality) are partially or fully down. Other issued assets on Liquid, such as USDT and various tokenized real world assets, are reported as not directly exploited but are effectively stuck while the network is paused.
If you hold L-BTC or other Liquid assets, the immediate risk is liquidity and access, not Bitcoin chain safety, and peg value will depend on how much BTC actually comes back.
3. What To Watch Next
Blockstream has announced that bridge nodes are now patched and safe to return the funds, clearing the way for the attackers to send BTC back to the federation wallet once they are satisfied, according to TradingView coverage of the follow up. However, as of latest reports, the full 4,000 BTC remain under the attackers control, and their offer is to return most funds, not necessarily all.
Security experts, including Ledgers CTO, have publicly questioned calling this a true white-hat action, since draining hundreds of millions and then negotiating on chain looks more like a high leverage exploit than a traditional coordinated disclosure. The open questions are whether the attackers really return the bulk of the BTC, how any shortfall is allocated (federation vs users), and how quickly Liquid can safely resume peg-outs.
The key signals to monitor are on-chain movements from the known exploit address, official recovery and compensation plans from Blockstream and Liquid Federation members, and any structural changes to how Liquid handles collateral and validation.
Conclusion
This incident shows that while Bitcoins base layer remains intact, complex sidechains and bridges can create concentrated points of failure with system-wide consequences when they break. Whether the attackers truly behave like white hats and return most of the 4,000 BTC will determine how painful this is for L-BTC holders and how much trust remains in Liquid-style federated sidechains.
