Key Highlights
- Approximately 4,000 BTC valued at $320 million were extracted from Liquid Network’s federation wallet by individuals claiming to be ethical hackers
- The vulnerability originated from a code defect in Elements, the open-source framework underlying Liquid, rather than a security key breach
- The withdrawal process utilized SideSwap, an authorized trading interface, complicating early identification efforts
- The individuals responsible are establishing contact with Blockstream through blockchain-based Bitcoin communications and have pledged fund restitution following vulnerability remediation
- Alternative digital assets on the platform, including USDT, remained secure and unaffected
Liquid Network, a Bitcoin layer-two solution facilitating accelerated transaction settlements for cryptocurrency exchanges, has suspended all network activity following the extraction of approximately $320 million in Bitcoin by actors identifying themselves as white-hat security researchers.
The security breach occurred on Sunday, September 7, when parties claiming ethical hacking credentials extracted roughly 4,000 of the 4,200 Bitcoin stored within Liquid’s federated custody wallet. This represents approximately 95% of the network’s entire Bitcoin reserves.
Understanding Liquid Network’s Infrastructure
Blockstream introduced Liquid Network in 2018 as a specialized sidechain operating alongside Bitcoin’s primary blockchain, engineered to enable cryptocurrency exchanges to execute settlements with significantly reduced latency compared to Bitcoin’s base layer.
The platform generates L-BTC tokens, which maintain a 1:1 peg with authentic Bitcoin secured in a federation wallet. This federation comprises over 80 participating entities, including major exchanges, blockchain infrastructure providers, and institutional asset management firms.
The near-complete depletion of these reserves has sparked significant concerns regarding the fundamental security architecture of this settlement infrastructure.
Technical Details of the Security Breach
Unlike typical cryptocurrency compromises observed throughout the current year, this incident did not result from credential theft or private key exposure.
Rather, a programming defect within Elements, the open-source codebase powering Liquid’s operations, enabled the creation of Bitcoin units without legitimate backing. These fabricated assets were subsequently transferred through SideSwap, a legitimate and authorized exchange interface operating within the network ecosystem.
SideSwap representatives confirmed their Peg-out Authorization Key remained secure and uncompromised. The platform stated it lacked the technical capability to distinguish between legitimately backed coins and those generated through the vulnerability, resulting in uniform processing of all withdrawal requests.
Cybersecurity analysts indicate the defect exists within the node-level architecture of Liquid’s transaction processing infrastructure, separate from hardware security modules or cryptographic key management protocols.
The individuals responsible have initiated communication with Blockstream through on-chain Bitcoin messaging protocols. One transmitted message stated: “Please fix the bug first. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
According to Alex Thorn, Galaxy Digital’s head of research, the hackers additionally transmitted encrypted technical documentation to Blockstream personnel, providing detailed information to assist in vulnerability identification and remediation efforts.
As of this publication, the extracted Bitcoin remains unreturned and network operations continue to be suspended. Bridge node infrastructure has been deactivated, with participating exchanges either implementing or preparing to implement restrictions on L-BTC deposit and withdrawal capabilities.
Liquid Network officials verified that alternative digital assets hosted on their infrastructure, including Tether (USDT), DePix tokens, and tokenized real-world assets, experienced no security compromise.
This security event arrives shortly after a $6 million exploit targeting a decentralized lending protocol associated with Crypto.com last week, as well as a previous security incident involving Coldcard hardware wallet infrastructure. Liquid Network has not yet provided a specific timeframe for network restoration and resumption of normal operations.


