Need help? Support
BITCOIN
Tether Dominance USDT.D

BTC sidechain hackers plan 4,000 BTC return

Published 559 words 3 min read

TLDR

Hackers who drained about 4,000 BTC from Bitcoin sidechain Liquid say they will return most of the funds after a bug fix, but the coins are still in their wallet.

  1. Purported white-hat hackers exploited a software bug to pull roughly 4,000 BTC from Liquids federation wallet, then opened on-chain negotiations to return funds.
  2. The incident left Liquids wrapped bitcoin (L-BTC) massively undercollateralized, affecting that sidechain and its users, not Bitcoins base chain.
  3. The key catalysts now are full patching of Liquids software, whether funds are actually returned, and how any remaining shortfall is handled.

Deep Dive

1. What Happened In The Hack

Liquid Network, a Bitcoin (BTC) sidechain run by Blockstream, paused operations after actors claiming to be white-hat hackers withdrew about 4,000 BTC (around 320 million dollars) from its federation wallet using a bug in the Elements software and the SideSwap peg-out flow. Reports describe how the attacker left an on-chain message saying we are whitehats. contact us on chain and later told Blockstream they would return most of the bitcoin once the vulnerability is fixed and all nodes are patched. This pledge to return funds after a bug fix is detailed in several updates, including a summary of the attackers messages and Blockstreams replies in which the team acknowledges the condition to fix the bug first before the return.

What this means

There is a stated plan to give most coins back, but it is voluntary and not yet fulfilled, so users should treat it as a possibility, not a certainty.

2. Impact On Liquid And BTC Users

The exploit drained nearly all of Liquids reserves, leaving L-BTC backed by only a small fraction of the required bitcoin according to incident overviews that note reserves dropped from over 4,200 BTC to under 200 BTC. Exchanges have paused L-BTC deposits and withdrawals, and Liquid disabled bridge nodes to halt new transactions while it investigates and patches the bug. Importantly, coverage stresses that this is a sidechain and bridge incident and does not mean Bitcoins base protocol or its main-chain security were compromised.

What this means

The direct risk is to users holding or using L-BTC and Liquid-based assets, not to BTC held on the main chain, but the event damages confidence in wrapped and bridged Bitcoin.

3. What To Watch Next

Blockstream has since announced that bridge nodes are patched and safe to return the funds, clearing the path technically for the attacker to send the BTC back. At the same time, follow-up reporting notes that as of the latest updates, the roughly 4,000 BTC still sit under the attackers control while they insist on confirming the fix across the network first. Markets will watch three outcomes: how much BTC is actually returned, how any unrecovered shortfall is allocated among federation members and users, and whether this triggers tighter security expectations for Bitcoin sidechains and bridges.

What this means

The real resolution hinges on on-chain movement of the stolen BTC; until that happens, L-BTC users face uncertainty around peg value and eventual compensation.

Conclusion

The Liquid Network hack shows how a single software bug in a Bitcoin sidechain can create hundreds of millions in contingent losses, even without touching the Bitcoin base chain. Hackers say they will return most of the roughly 4,000 BTC after Blockstreams fixes, but until coins actually move back, L-BTC and Liquid users are exposed to peg and recovery risk that may reshape how the market treats wrapped Bitcoin and sidechain security.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top