Bitcoin3 mins read

Bitcoin’s Liquid Network Exploit: $320 Million Drained, $47 Million Kept in Disputed ‘White Hat’ Operation

A concise outline of Gizmodo’s report on the Liquid Network exploit, how attackers created unbacked L-BTC, why the “white hat” claim is disputed, and what the incident means for trust in Bitcoin sidechains.

The Core Incident: A $320 Million Drain With Most Funds Returned

The Liquid Network, a Bitcoin sidechain developed by Blockstream, was drained of roughly 4,000 bitcoin worth about $320 million on Sunday, according to Gizmodo. The attackers described themselves as white hat hackers and communicated with Blockstream through OP_RETURN messages embedded in Bitcoin transactions. They later returned 3,400 bitcoin to the Liquid federation while keeping 598.5 bitcoin, described as roughly $47 million. The central unresolved issue is whether this was a legitimate security intervention, extortion, or something in between.

How the Exploit Reportedly Worked

The incident does not appear to have involved compromised keys from the multisig address securing the network on Bitcoin’s base blockchain. Instead, Gizmodo reports that an apparent bug in Liquid’s node software allowed attackers to create unbacked Liquid Bitcoin, or L-BTC, and use those coins to trigger a peg-out back to Bitcoin. Some nodes rejected the exploit transaction and stalled at block height 4,050,335, but the relevant peg-out nodes were running the new software. The federation ultimately released roughly 3,996 bitcoin to an address controlled by the attacker.

Why Liquid’s Security Model Is Under Scrutiny

Liquid is operated by the Liquid Federation, which includes Bitcoin-focused companies such as exchanges, trading firms, wallet providers, and infrastructure businesses. The network has more than 80 members, while 15 currently operate specialized functionaries that produce and sign Liquid blocks and secure the federation’s 11-of-15 multisig wallet. Gizmodo notes that the exploit has fueled criticism that Liquid’s practical security depended heavily on software behavior, not only the multisig setup. SideSwap’s role in processing the peg-out is also drawing scrutiny because Liquid’s peg-out system is designed to restrict withdrawals to authorized federation members and whitelisted Bitcoin destinations.

The ‘White Hat’ Question Remains Unsettled

Bitcoin Liquid Network Hacker Message
Image credits:Mempool.space

The attackers repeatedly said they were white hats and demanded that the vulnerability be fixed before returning most of the bitcoin. Gizmodo reports that Blockstream told the hackers the relevant bridge nodes had been patched, after which the hackers confirmed the return address and later sent back 3,400 bitcoin. The fact that they kept 598.5 bitcoin keeps the legal and ethical question open. The episode highlights why “white hat” claims are not self-proving when funds are taken first and returned only in part.

What Readers Should Take Away

Gizmodo reports that Bitcoin’s base blockchain and Bitcoin Core software were not affected by this incident. The immediate concern is trust in Liquid and in sidechain systems that rely on complex software, federation processes, and peg-out controls. For users, the practical takeaway is to treat sidechains and wrapped or pegged assets as distinct risk environments rather than assuming they carry the same security profile as base-layer bitcoin. The broader crypto security lesson is that key custody, node software, bridge logic, and operational procedures all matter when large amounts of value can move quickly.

Discover More

    Bitcoin coins cryptocurrency on U.S. dollar banknotes background.
    Coldcard Bug Crypto Thefts

    A Coldcard wallet flaw is being tied to more than $130 million in stolen cryptocurrency.

    CryptocurrencyCybersecurity