Liquid Network, a Bitcoin Layer 2 network, reported a security incident where approximately 4,000 BTC ($320 million) was withdrawn from the Liquid Federation wallet by individuals claiming to be white-hat hackers. Blockstream is communicating with the hackers through signed on-chain messages. The hackers maintain that a network bug must be fixed before they will return the funds. Liquid stated that the Peg-out Authorization Key was not compromised and that other assets on the network remain unaffected. The network has paused operations by disabling bridge nodes while it addresses the issue.
Liquid Network reported a security incident in which purported white-hat hackers withdrew approximately 4,000 BTC, worth $320 million, from the Liquid Federation wallet. Blockstream is attempting to contact the parties involved through a signed on-chain message.
In an update, Liquid stated the funds were withdrawn using the SideSwap PAK (Peg-out Authorization Key) but that the key itself was not compromised. Crypto exchanges have been informed and have already suspended, or are preparing to suspend, LBTC deposits and withdrawals.
Other assets on the network, including USDT, DePix and real-world assets, were not affected. The network has temporarily disabled its bridge nodes, meaning new transactions cannot be submitted, effectively pausing the sidechain.
Liquid said, “Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.”
The public back-and-forth between Blockstream and the party claiming to be the white-hat hacker is continuing on-chain. According to Samson Mow, the hacker appears to prefer communicating publicly rather than via email, posting messages through Bitcoin transaction data.
The exchange began at 11:30 AM PDT, when the hacker wrote, “we are whitehats. contact us on chain.” Blockstream responded at 12:31 PM on September 6, asking the hacker to contact its security team by email.
At 7:20 PM, the hacker said they planned to send most of the funds back and asked whether a specified address was acceptable. About an hour later, they said the bug needed to be fixed first, adding, “The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
Blockstream replied, “Yes, thank you,” at 8:30 PM. As of 9:12 PM PDT, around 3,998.5 BTC remained unmoved.
Ledger CTO Charles Guillemet was skeptical of the white-hat claim, pointing out that legitimate security researchers would not typically drain a bridge and then ask to be contacted on-chain. He drew parallels with the Ronin hack and the Euler exploit, noting that criminal groups do not typically reach out to their victims either.
