
A Coldcard wallet flaw is being tied to more than $130 million in stolen cryptocurrency.
A concise outline of Gizmodo’s report on the Liquid Network exploit, how attackers created unbacked L-BTC, why the “white hat” claim is disputed, and what the incident means for trust in Bitcoin sidechains.

The Liquid Network, a Bitcoin sidechain developed by Blockstream, was drained of roughly 4,000 bitcoin worth about $320 million on Sunday, according to Gizmodo. The attackers described themselves as white hat hackers and communicated with Blockstream through OP_RETURN messages embedded in Bitcoin transactions. They later returned 3,400 bitcoin to the Liquid federation while keeping 598.5 bitcoin, described as roughly $47 million. The central unresolved issue is whether this was a legitimate security intervention, extortion, or something in between.
The incident does not appear to have involved compromised keys from the multisig address securing the network on Bitcoin’s base blockchain. Instead, Gizmodo reports that an apparent bug in Liquid’s node software allowed attackers to create unbacked Liquid Bitcoin, or L-BTC, and use those coins to trigger a peg-out back to Bitcoin. Some nodes rejected the exploit transaction and stalled at block height 4,050,335, but the relevant peg-out nodes were running the new software. The federation ultimately released roughly 3,996 bitcoin to an address controlled by the attacker.
Liquid is operated by the Liquid Federation, which includes Bitcoin-focused companies such as exchanges, trading firms, wallet providers, and infrastructure businesses. The network has more than 80 members, while 15 currently operate specialized functionaries that produce and sign Liquid blocks and secure the federation’s 11-of-15 multisig wallet. Gizmodo notes that the exploit has fueled criticism that Liquid’s practical security depended heavily on software behavior, not only the multisig setup. SideSwap’s role in processing the peg-out is also drawing scrutiny because Liquid’s peg-out system is designed to restrict withdrawals to authorized federation members and whitelisted Bitcoin destinations.

The attackers repeatedly said they were white hats and demanded that the vulnerability be fixed before returning most of the bitcoin. Gizmodo reports that Blockstream told the hackers the relevant bridge nodes had been patched, after which the hackers confirmed the return address and later sent back 3,400 bitcoin. The fact that they kept 598.5 bitcoin keeps the legal and ethical question open. The episode highlights why “white hat” claims are not self-proving when funds are taken first and returned only in part.
Gizmodo reports that Bitcoin’s base blockchain and Bitcoin Core software were not affected by this incident. The immediate concern is trust in Liquid and in sidechain systems that rely on complex software, federation processes, and peg-out controls. For users, the practical takeaway is to treat sidechains and wrapped or pegged assets as distinct risk environments rather than assuming they carry the same security profile as base-layer bitcoin. The broader crypto security lesson is that key custody, node software, bridge logic, and operational procedures all matter when large amounts of value can move quickly.

A Coldcard wallet flaw is being tied to more than $130 million in stolen cryptocurrency.