Newsroom

Purported White Hats Drain $320 Million in Bitcoin From Liquid Network, Pledge Return After Fix

7 September, 2026   /   News   /  AI   /   Tags:  federation, btc, sideswap, blockstream, peg

Purported White Hats Drain $320 Million in Bitcoin From Liquid Network, Pledge Return After Fix

Nearly 4,000 BTC left the federation wallet on Sunday after a software bug allowed unauthorized L-BTC creation, prompting a full network pause while on-chain talks continue

Approximately 4,000 bitcoin valued at roughly $320 million were withdrawn from the Liquid Network federation wallet on September 6 in a security incident that has left the Bitcoin sidechain paused. The actors behind the transfer described themselves as white-hat hackers and later stated they intend to return most of the funds once a critical vulnerability is patched across the network.

The withdrawal accounted for about 95 percent of the roughly 4,200 BTC that had been pegged into Liquid. On-chain records show a peg-out of approximately 3,996 BTC processed through the SideSwap service, leaving the federation wallet with around 197 BTC. The receiving address later consolidated the funds and attached an OP_RETURN message reading “we are whitehats. contact us on chain.”

How the Withdrawal Occurred

Liquid Network, a Bitcoin sidechain developed by Blockstream and operated by a federation of more than 80 members, confirmed the incident in a public statement. The funds moved via SideSwap’s Peg-out Authorization Key, a mechanism designed to authorize legitimate withdrawals. Both Liquid and SideSwap stated that the key itself was not compromised and that no other federation keys were affected.

SideSwap reported that a customer submitted 4,000 L-BTC to its peg-out service at 14:05 UTC. The service processed the request under standard procedures, burning the L-BTC and receiving a valid authorization. Twenty-three minutes later the federation released about 3,996 BTC to the customer’s Bitcoin address. Blockstream subsequently determined that the L-BTC in question had been created through a bug in Elements, the open-source software that powers Liquid’s confidential transactions and node operations.

Because the tokens passed network validation, SideSwap could not distinguish them from legitimate L-BTC. The bug appears to have allowed improperly minted coins to be treated as valid, enabling a normal peg-out process that drained nearly the entire reserve. Other assets issued on Liquid, including USDT, DePix and tokenized real-world assets, were not affected.

Key figures from the incident: roughly 4,000 BTC withdrawn (≈$320 million),representing 95 percent of Liquid’s pegged Bitcoin reserves; federation wallet left with approximately 197 BTC.

Network Response and Communication

Liquid immediately disabled its bridge nodes, preventing new transactions from being submitted and effectively pausing the sidechain. The project also notified crypto exchanges, which have suspended or are preparing to suspend L-BTC deposits and withdrawals. In its statement Liquid said federation members were working to resolve the issue and restore normal activity, adding that Liquid wallets would be impacted.

Blockstream initiated contact with the address controlling the funds through on-chain messages. At Bitcoin block 965,822 the company sent 1,000 satoshis accompanied by an OP_RETURN note directing the parties to its security team. A follow-up transaction carried PGP-encrypted material signed with Blockstream’s published public key.

The actors responded at block 965,869 by moving their balance and sending 1,000 satoshis back to the federation peg wallet. Their message asked whether returning most of the funds to a designated federation address would be acceptable, while stating that the vulnerability must first be fixed and every node patched. “Please fix the bug first,” they wrote, adding that the chain remained at risk until the update was confirmed across the network. They also supplied encrypted technical details readable only by Blockstream.

“we are whitehats. contact us on chain.”
Message attached to the consolidation transaction

As of the latest available reports, approximately 3,998.5 BTC remained under the control of the address. No further transfers or messages had been recorded after the evening of September 6.

Questions Over White-Hat Status

Liquid has consistently referred to the parties as “purported” white-hat hackers. Ledger Chief Technology Officer Charles Guillemet initially expressed skepticism, noting that conventional security researchers typically do not drain hundreds of millions of dollars from a bridge and then solicit contact on-chain. He compared the episode to previous large exploits such as Ronin and Euler.

After the on-chain dialogue began, Guillemet revised his assessment, observing that criminal groups rarely attempt to communicate with their targets. He suggested the actors might be researchers who used advanced tools to identify the vulnerability without following standard disclosure channels.

The use of the word “most” in the actors’ pledge leaves open the possibility that a portion of the bitcoin could be retained. There is also no confirmation that the funds will ultimately be returned. Until the bitcoin is transferred back to the federation, the white-hat designation remains an unverified claim.

Broader Context for Federated Bridges

Liquid relies on a strong federation model in which a threshold of functionaries must approve blocks and peg-out transactions. The Peg-out Authorization Key system was intended to prevent even compromised functionaries from redirecting user funds to arbitrary addresses. In this case the authorization pathway itself functioned as designed; the failure originated earlier in the creation of the L-BTC.

The incident has drawn attention to the operational risks inherent in federated sidechains and bridges. Industry data from the first half of 2026 indicated that infrastructure and operational vulnerabilities accounted for a disproportionate share of total losses even when they represented a minority of incidents. Blockstream has previously outlined work on reducing reliance on trust-based designs, including research into BitVM-based bridge models.

For now the Liquid Network remains paused while the technical patch is prepared and the on-chain discussion continues. The outcome will depend on whether the identified bug is fully remediated and whether the parties controlling the withdrawn bitcoin follow through on their stated intention to return the majority of the funds.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.