The Liquid Network, a Bitcoin sidechain developed by Blockstream, halted all operations after purported white-hat hackers exploited a vulnerability to withdraw approximately 4,000 BTC, valued at roughly $320 million, from the network's federation reserves Bitcoin Magazine. The incident marks one of the largest security breaches affecting a Bitcoin sidechain infrastructure to date.
The attackers, who identified themselves as white-hat hackers, communicated their intentions through PGP-signed messages embedded in Bitcoin transactions Decrypt. They informed Blockstream that they would return most of the stolen funds after the Elements vulnerability—underlying Liquid's codebase—was patched across the network Cointelegraph. This unusual arrangement allowed for direct negotiation between the exploiters and Blockstream developers through on-chain messaging.
Following the disclosure, Blockstream disabled bridge nodes and paused the sidechain entirely to prevent further unauthorized withdrawals Bitcoin Magazine. The network serves as a settlement layer used by cryptocurrency exchanges, meaning the operational halt affected institutional participants relying on Liquid for faster Bitcoin transactions and confidential asset transfers.
After Blockstream confirmed that Liquid's bridge nodes had been patched, the attackers proceeded to return approximately 3,400 BTC of the original 4,000 BTC taken The Block. The returned funds represent roughly $270 million at prevailing prices, leaving approximately 598.5 BTC—valued at nearly $50 million—still outstanding Decrypt. Blockstream communicated the patch completion to the actors through the same on-chain messaging system used throughout the incident.
The exploit specifically targeted the federation wallet backing L-BTC, the wrapped Bitcoin representation on the Liquid sidechain Bitcoin Magazine. Unlike decentralized bridge protocols where exploits have become increasingly common, Liquid operates through a federated security model where functionaries validate peg-in and peg-out operations between the main Bitcoin chain and the sidechain. The vulnerability apparently allowed the attackers to bypass these safeguards and drain the reserves directly.
The characterization of the attackers as "white hats" remains disputed within security circles, as the withdrawal of $320 million before any coordinated disclosure or patch implementation diverges from standard responsible disclosure practices. However, the subsequent return of the majority of funds following the security fix has complicated straightforward categorization of the incident as purely malicious CoinDesk. The retained 600 BTC represents either a bounty demand, operational costs, or simply unreturned portion of the exploit.
The incident highlights ongoing security challenges for Bitcoin layer-2 solutions and federated sidechains, which trade decentralization guarantees for scalability and privacy features. Liquid Network's pause affected exchange settlement operations during the resolution period, demonstrating systemic dependencies that can cascade from sidechain infrastructure failures.