Liquid Network Pauses After Purported White Hats Drain 4,000 Bitcoin (BTC)
Liquid Network paused after purported white hats withdrew about 4,000 BTC worth $320M, pledging to return most funds once Blockstream patches the bug.
AI SummaryAI
- Liquid Network paused after roughly 4,000 BTC worth about $320 million left its federation wallet
- The withdrawal equaled approximately 95% of Liquid's roughly 4,200 BTC reserve
- The actors offered to return most funds only after Blockstream patches the Elements bug
- A peg-out of about 3,996 BTC was confirmed in Bitcoin block 965,783 on Sept. 6
4,000 BTC Leaves the Federation Wallet
The Bitcoin (BTC) sidechain Liquid Network has halted operations after approximately 4,000 BTC, valued near $320 million, was pulled out of its federation wallet by actors describing themselves as white-hat hackers. In a message posted on X, Liquid confirmed that bridge nodes were disabled to block new transactions and that trading platforms — including many of the venues in our best crypto exchanges roundup — were told to suspend L-BTC deposits and withdrawals. The withdrawn sum represents roughly 95% of the approximately 4,200 BTC held in the federation reserve beforehand. L-BTC works as a wrapped Bitcoin instrument, minted 1:1 against coins locked on the sidechain. The Bitcoin network itself was untouched — the base proof-of-work chain kept producing blocks normally, because the fault sits in Liquid's infrastructure, not the mainnet.
On-Chain Talks With Blockstream
Since Sunday, the group has opened a negotiation channel using OP_RETURN messages and PGP-encrypted text embedded in Bitcoin transactions. A reconstruction published by Galaxy Research head Alex Thorn shows Blockstream, Liquid's technology provider, initiating contact by sending 1,000 satoshis alongside a note directing the recipient to its security team. Before that, roughly $320 million in coins had been consolidated into a single Bitcoin address tagged with the message “we are whitehats. contact us on chain.” The actors asked whether returning most of the funds to the federation address would be acceptable, while insisting the coins stay put until the bug is fixed across the network. How much “most” means is undefined, no repayment is guaranteed, and nearly all of the Bitcoin remains under their control.
SideSwap Says Its Key Was Not Compromised
The routing of the withdrawal is coming into focus. SideSwap disclosed that the transaction passed through its peg-out service as a customer order using its Peg-out Authorization Key (PAK), but stated that the key itself was never compromised. Instead, the L-BTC involved originated from a bug in Elements, the open-source software underpinning Liquid. Liquid has so far described those responsible only as “purported” white-hat hackers, keeping the question of intent open. Assets issued on the network besides L-BTC — including USDT, DePix and real-world tokens — were reportedly untouched. For anyone tracking how wrapped-Bitcoin designs concentrate custody risk, the episode is a live case study, and our earlier 4,000 BTC white-hat peg-out report walks through the bridge mechanics in detail.
The Timeline Written on Bitcoin Blocks
On-chain data pins the exit itself to a peg-out of about 3,996 BTC whose corresponding Bitcoin transaction was confirmed in block 965,783 on Sept. 6 — viewable on a block explorer. A separate transaction carried the opening claim of white-hat status. Blockstream followed at block 965,822 with 1,000 satoshis and an OP_RETURN alert, then transmitted encrypted material with a detached signature verifiable against its published PGP key. The actors answered at block 965,869, sending 1,000 satoshis to the federation's peg wallet and asking about returning most of the funds; their demand to “fix the bug first” and update every node arrived six blocks later. The exchange proves whoever holds the coins can respond to Blockstream — it does not prove their motives.
Sector Split on the White-Hat Claim
Security specialists remain divided. Ledger Chief Technology Officer Charles Guillemet first argued that conventional white hats do not typically drain hundreds of millions of dollars from a bridge, drawing comparisons with past exploits such as Ronin and Euler. After the group attempted contact, he softened his position, noting that criminal actors rarely go to such lengths to reach their victims and writing that “there's hope” — while speculating that AI-assisted research could have surfaced the flaw without a formal disclosure process. Liquid has not named a patch version, published a technical postmortem or set a reopening time, and no confirmed return transaction had appeared as of the latest checks.
Post-Mortem Still Missing
In our reading, the verifiable layer is what separates this incident from a standard exploit: the drained amount, roughly 3,996 BTC, is independently confirmable on-chain, and the team's own messaging locates the root cause in Elements software rather than stolen authorization keys. The remediation path is equally explicit — a patch distributed across every federation node before any restart. What remains unproven is intent; until a formal post-mortem discloses how the peg-out bypassed normal controls and how much of the reserve the actors intend to keep, the “white hat” framing stays disputed. For Bitcoin DeFi, it repeats a familiar lesson: bridges holding concentrated custody remain the year's weakest link, with 2026 protocol losses already estimated at $1.3 billion through August.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


