Hackers Steal $320 Million in Crypto From Bitcoin Network Used by Exchanges: What the Company Has to Say
A major security incident has shaken the cryptocurrency industry after roughly 4,000 Bitcoin, worth about $320 million, were withdrawn from the federation wallet backing the Liquid Network, a Bitcoin sidechain used by cryptocurrency exchanges and other financial institutions. The incident occurred on September 6 and represents roughly 95% of the Bitcoin that had been held in the wallet.
Liquid Network, developed by Blockstream, immediately treated the event as a serious security incident and temporarily halted network activity. The company disabled its bridge nodes, preventing new transactions, while exchanges were asked to suspend or prepare to suspend deposits and withdrawals involving L-BTC, Liquid’s Bitcoin-backed asset.
What makes the incident unusual is that Liquid is not describing the perpetrators simply as ordinary hackers. The company referred to them as “purported white-hat hackers,” meaning people claiming they exploited the vulnerability in order to expose and contain a security problem rather than permanently steal the funds. However, that characterization has not been independently verified.
The attackers themselves left an on-chain message stating that they were “whitehats” and asking Liquid to contact them through the blockchain. Blockstream subsequently attempted to establish communication with them using signed and encrypted messages.
The company has emphasized an important point: the cryptographic key used for the withdrawal was not compromised. Liquid said the funds were withdrawn through SideSwap’s Peg-out Authorization Key, or PAK, but that the PAK itself and other federation keys were not stolen.
That distinction is central to understanding the attack. The incident apparently did not involve someone simply stealing a private key and signing an unauthorized transaction. Instead, investigators have focused on a vulnerability in the software and the process used to authorize Bitcoin withdrawals from Liquid back to the Bitcoin blockchain.
SideSwap, which operates the relevant peg-out service, said the affected transaction involved approximately 4,000 L-BTC being sent to its peg-out service. The L-BTC was then burned using what appeared to be a valid authorization, after which the Liquid Federation released approximately 3,996 BTC to the destination address.
Subsequent investigation pointed toward a vulnerability in Elements, the open-source software underlying Liquid’s technology. On-chain researchers reported that the attackers were apparently able to create L-BTC through a software flaw and then redeem those tokens for real Bitcoin held by the federation.
This is why the attack is particularly significant for the cryptocurrency industry. Bitcoin itself was not hacked. The Bitcoin blockchain continued operating normally. Instead, the vulnerability existed in an additional infrastructure layer built around Bitcoin.
Liquid exists precisely because exchanges and institutions want faster Bitcoin settlement and additional functionality. Rather than conducting every transaction directly on Bitcoin’s main network, users can use Liquid and its L-BTC system. But that additional functionality also introduces additional software, custody and federation mechanisms that can become targets for attackers.
The scale of the withdrawal was enormous. Liquid reportedly held approximately 4,200 BTC before the incident, meaning nearly the entire Bitcoin reserve was removed. The remaining reserves were only a small fraction of the original holdings.
The immediate impact was therefore not limited to Blockstream or Liquid’s federation. Exchanges using the network had to react by restricting L-BTC movements, while Liquid users faced interruptions to normal transactions. Liquid warned that its wallets would be affected while federation members worked to resolve the problem.
There was, however, a dramatic development after the initial theft. The party holding the Bitcoin told Blockstream that most of the funds would be returned once the vulnerability was fixed and every relevant node had been patched. The attackers specifically insisted that the software problem needed to be addressed before the Bitcoin would be sent back.
Blockstream subsequently told the attackers that its bridge nodes had been patched. Following that confirmation, approximately 3,400 BTC was returned to the federation, according to The Block. Around 598.5 BTC, worth roughly $47 million, remained in the attacker’s wallet at the time of that report.
That development substantially changes the financial impact of the incident, but it does not eliminate the security concerns. A vulnerability was apparently powerful enough to cause the release of nearly the entire Bitcoin reserve, demonstrating that even sophisticated federation and authorization systems can be undermined by flaws elsewhere in the software stack.
The incident also raises questions about the term “white-hat hacker.” A conventional security researcher would normally disclose a vulnerability to the affected company before moving hundreds of millions of dollars. In this case, the funds were withdrawn first and the explanation came afterward, leading some security experts to question whether the actors should truly be regarded as ethical hackers.
At the same time, the attackers’ subsequent return of most of the Bitcoin and their insistence that the underlying vulnerability be fixed provide evidence supporting their claim that they were attempting to force the network operators to address a dangerous flaw.
For Blockstream and Liquid, the priority is now restoring the network safely rather than simply recovering the missing Bitcoin. The company must establish exactly how the fraudulent or improperly created L-BTC passed through the peg-out mechanism, patch every affected node and ensure that the same vulnerability cannot be exploited again.
The incident is another reminder that Bitcoin’s security and the security of Bitcoin-based financial infrastructure are two different things. Bitcoin’s underlying blockchain was not compromised, yet hundreds of millions of dollars in Bitcoin could still be put at risk because of a vulnerability in a system built around it.
The biggest remaining question is what happens to the approximately $47 million still held by the attacker and whether the full incident can ultimately be resolved without losses to Liquid users or federation members. The return of most of the funds is encouraging, but the episode has exposed a potentially serious weakness in one of the networks used to move Bitcoin between major market participants.
