Bitcoin sidechain Liquid Community has been paused after roughly 4,000 BTC price about $320 million was withdrawn from the federation pockets backing its L-BTC token, in an incident that seems to have exploited a vulnerability within the community’s underlying software program somewhat than compromised its cryptographic keys.
Liquid confirmed on Sunday that purported “white-hat hackers” had eliminated round 4,000 BTC from the federation’s reserves. The community subsequently disabled its bridge nodes, stopping new transactions, whereas exchanges had been requested to droop L-BTC deposits and withdrawals.
The withdrawal represented about 95% of the roughly 4,200 BTC held within the federation pockets earlier than the incident. Bitcoin’s most important community was not affected.

Liquid Community’s Assertion on X (Supply: X)
A legitimate-looking peg-out
The incident unfolded by means of Liquid’s regular peg-out course of, making the exploit notably vital.
SideSwap, a Liquid federation member that operates a peg-out service, stated a buyer despatched 4,000 L-BTC to its service at roughly 14:05 UTC on September 6. The tokens had been burned underneath a sound Peg-out Authorization Key (PAK) authorization.
About 23 minutes later, the Liquid Federation launched roughly 3,996 BTC to the shopper’s Bitcoin handle.
Liquid stated the transaction used SideSwap’s PAK however pressured that the important thing itself had not been compromised. SideSwap likewise stated none of its techniques had been breached.
As a substitute, the L-BTC used within the transaction seems to have been created by means of a vulnerability in Components, the open-source software program that underpins Liquid.
That distinction is central to the incident. The attacker didn’t apparently have to steal a federation key or break into SideSwap’s infrastructure. As a substitute, the vulnerability allowed L-BTC that ought to not have existed to enter the conventional redemption course of. As soon as these tokens handed the required checks, the federation paid out actual BTC in opposition to them.
The federation pockets, which held greater than 4,200 BTC earlier than the transaction, was left with roughly 200 BTC afterward.
The exact technical root trigger has not been publicly detailed by Blockstream or Liquid. A repair for the underlying vulnerability had already been added to the software program codebase earlier than the incident, however the difficulty had not been totally resolved throughout the community when the exploit occurred.
The hackers name themselves white hats
The celebration controlling the withdrawn bitcoin later left an on-chain message saying, “we’re whitehats. contact us on chain.”
They left a message. (Supply: memepool)
Blockstream responded by means of a signed Bitcoin transaction, offering an e mail handle for contact. The 2 sides subsequently exchanged further messages, together with PGP-signed communications recorded on-chain.
The purported hackers supplied to return many of the funds however connected a situation: Liquid should first patch the vulnerability and make sure that each node working the community is up to date.
The actors additionally reportedly despatched encrypted technical particulars in regards to the vulnerability to Blockstream, in keeping with Galaxy Digital analysis head Alex Thorn.
Blockstream subsequently acknowledged the hackers’ situation and labored to patch the affected infrastructure. Nevertheless, the withdrawn bitcoin had not been returned on the time of publication.
The “white-hat” characterization has nonetheless been disputed.
Ledger Chief Know-how Officer Charles Guillemet questioned whether or not the actors ought to be thought of safety researchers, arguing that taking a whole bunch of thousands and thousands of {dollars} earlier than disclosure differs considerably from typical white-hat follow.
The controversy highlights an more and more tough distinction in crypto safety incidents: whether or not an actor who exploits a vulnerability, takes management of funds and later affords to return them after remediation ought to be handled as a safety researcher or an attacker demanding circumstances for restitution.
Liquid stays frozen
Liquid has saved its bridge infrastructure offline whereas federation members work on the vulnerability. Exchanges have additionally suspended, or ready to droop, L-BTC deposits and withdrawals.
Different belongings issued on Liquid, together with USDT, DePix and tokenized real-world belongings, had been reported to be unaffected by the incident. Nevertheless, the network-wide pause has disrupted companies that rely on Liquid’s potential to maneuver belongings between the sidechain and Bitcoin.
Liquid is a federated Bitcoin sidechain developed with Blockstream that’s designed to allow sooner, extra confidential transactions and assist the issuance of digital belongings. BTC is locked on Bitcoin’s mainnet and represented as L-BTC on Liquid, with federation members answerable for managing the bridge between the 2 networks.
That structure means the incident raises a broader query about the place safety dangers sit in sidechain techniques. On this case, the federation’s keys seem to have remained safe, but a flaw within the software program governing transaction validation was sufficient to place a considerable portion of the underlying reserves in danger.
For Liquid, the instant priorities are clear: totally patch the vulnerability, replace each affected node, decide whether or not the withdrawn bitcoin will likely be returned and set up that the bridge can safely reopen.
As of September 7, the funds remained exterior the federation’s management, whereas Liquid itself remained paused. The incident remains to be growing, and the total technical clarification of how roughly 4,000 BTC was in a position to depart the reserve pockets has but to be made public.





