Need help? Support
BITCOIN
Tether Dominance USDT.D

BTC sidechain whitehats plan $320M return

Published 572 words 3 min read

TLDR

Purported whitehat hackers drained around 4,000 BTC from Bitcoin sidechain Liquid Network and say they will return about 320 million dollars once a critical bug is fixed.

  1. Liquid Network, a Bitcoin sidechain, paused after an exploit used a software bug to withdraw roughly 4,000 BTC from its federation wallet.
  2. The attackers, claiming to be whitehats, told Blockstream they will return most funds after Liquid patches the vulnerability and updates all nodes.
  3. Until the fix and any return are confirmed, LBTC users face peg and access risk, and the incident underscores broader sidechain and bridge security concerns.

Deep Dive

1. What Happened On Liquid

Reports say about 4,000 BTC, worth around 320 million dollars, were withdrawn from Liquid Networks federation wallet, representing roughly 95 percent of its reported reserves before the incident. Liquids statement confirms the network disabled bridge nodes and exchanges halted Liquid Bitcoin (LBTC) deposits and withdrawals.

SideSwap, a federation member, explained that the withdrawal passed through its peg out service using its Peg out Authorization Key (PAK), but the BTC backing the LBTC came from a bug in Elements, the software that underpins Liquid, rather than a compromised key or SideSwaps own systems. Further coverage describes it as an inflation style bug that allowed creation of unbacked L BTC, then a normal looking peg out.

2. Whitehats Plan To Return Funds

Actors embedded an on chain message stating we are whitehats. contact us on chain and have since exchanged signed messages with Blockstream, Liquids technology provider. According to CryptoPotatos incident summary, they say they will return the money back safely once the bug is fixed and every node is patched.

They reportedly sent encrypted technical details of the exploit and insisted the chain remains at risk at the latest code commit, asking that all nodes be updated before any return. As of the latest reports, most of the roughly 4,000 BTC remains unmoved and the pledge is conditional and unfulfilled. Some security experts, such as Ledgers CTO, have publicly questioned whether this behavior truly fits whitehat norms.

What this means

There is a credible communication channel and a conditional promise, but recovery is not guaranteed and depends entirely on the attackers follow through after Liquids patching.

3. Impact And What To Watch Next

LBTC is currently backed by only a small fraction of the BTC required for its 1 to 1 peg, and the sidechain is effectively frozen until federation members resolve the vulnerability and restart operations, as noted in Cointelegraphs coverage. Other assets issued on Liquid, such as USDT and tokenized real world assets, are reported as unaffected at the protocol level but still impacted by the network pause.

For crypto users, the key signals will be: 1) an official technical postmortem and patch rollout, 2) on chain evidence of BTC being returned, and 3) how LBTC trades once peg outs resume, including any discount or haircut for holders. More broadly, this joins a series of bridge and sidechain incidents that highlight that wrapped or federated BTC can carry additional protocol and governance risk beyond Bitcoin itself.

Conclusion

Liquids 320 million dollar incident shows how a single software bug in sidechain infrastructure can inflate wrapped assets and put peg reserves at risk, even without compromised keys. The attackers conditional promise to return funds, if honored, may limit direct losses, but the episode is likely to leave a lasting mark on trust in federated BTC solutions and reinforces the need to track not just base layer Bitcoin security, but also the robustness of any sidechains or bridges where BTC is parked.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top