Purported white-hat hackers withdrew approximately 3,998.5 BTC worth $319.5 million from Liquid Network's federation wallet on September 6, prompting the Bitcoin sidechain to pause all network activity while Blockstream worked to establish contact with the parties responsible. Liquid confirmed the incident in a post on X and said bridge nodes had been disabled, preventing any new transactions from entering the network.

"We are aware of a security incident on @Liquid_BTC," the network wrote, adding that federation members were actively working to resolve the situation.

The withdrawal represented roughly 95% of Liquid's reported bitcoin reserves, which stood at approximately 4,200 BTC before the incident, according to Lookonchain. Crypto exchanges were notified and either paused LBTC deposits and withdrawals or committed to do so. Other assets issued on Liquid, including USDT, DePix, and real-world assets, were unaffected.

How 4,000 BTC left without a key compromise

Liquid said the funds were withdrawn through the SideSwap PAK, a Peg-out Authorization Key used to authorize withdrawals from the Liquid federation back to the Bitcoin mainchain. The network stated that key had not been compromised, nor had any others, without explaining the root vulnerability that allowed the withdrawal to proceed.

An onchain message associated with the incident read:

"we are whitehats. contact us on chain."
Source: Arkham
Source: Arkham

Liquid Network is a Bitcoin sidechain developed by Blockstream that launched in 2018. It operates as a federated sidechain rather than a trustless bridge. A group of member companies, known as the federation, collectively control the peg mechanism. BTC locked on the Bitcoin mainchain is represented as LBTC on Liquid, with federation functionaries required to co-sign peg-out transactions back to mainchain. The federated model was a deliberate design choice prioritizing speed and confidentiality over the full trustlessness of the Bitcoin base layer, but it concentrates custody risk in the federation members rather than distributing it cryptographically. The SideSwap PAK system adds a second layer of authorization on top of the federation multisig for peg-outs, which makes the incident's mechanics unusual given that the key was reportedly not compromised in a conventional sense.

The onchain negotiation that followed

Alex Thorn, Head of Firmwide Research, reporting on the situation, documented a detailed back-and-forth between Blockstream and the purported white-hats conducted entirely through Bitcoin transactions and OP_RETURN messages.

In block 965,822, the Blockstream address sent 1,000 satoshis with the message "Please contact security at blockstream dot com." Block 965,865 carried an encrypted message with a detached PGP signature that verified against the key published at blockstream.com/pgp.txt. In block 965,869, the hackers replied by self-spending their balance while sending 1,000 satoshis to the federation's peg wallet with the message,

"Sending most back to [the federation address], is that ok."

The substantive response came in block 965,875. Again a self-spend with 1,000 satoshis sent to the federation, the OP_RETURN read:

"Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix."

Technical detail followed as a PGP message encrypted specifically to Blockstream's published key, meaning only Blockstream could read the contents.

Thorn described it simply: "Never a dull day in Bitcoin."

What the federation model means for recovery

The federated structure of Liquid creates a specific recovery dynamic that differs from a standard smart contract exploit. In a typical DeFi hack, stolen funds move through decentralized protocols where no single party controls the destination. In Liquid's case, the federation retains administrative capabilities over the network at a protocol level, and the white-hats' willingness to negotiate on-chain through PGP-authenticated messages suggests they anticipated that Blockstream could verify their identity and intent before any funds returned. The use of Blockstream's publicly published PGP key for encrypted technical communication indicates the white-hats wanted a private channel for vulnerability details while keeping the existence of negotiations publicly visible on-chain.

White-hat incidents of this scale have precedent in DeFi but are rarer on Bitcoin-adjacent infrastructure. The 2021 Poly Network exploit saw a hacker drain over $600 million across multiple chains before returning the funds after negotiations, citing the exploit as a demonstration rather than theft. Liquid's situation differs in that the white-hats explicitly conditioned the return on a confirmed patch rather than returning funds immediately.

Liquid said the word "most" in the hacker's message had not been further explained in public communications. The network did not disclose a timeline for restarting activity or the technical contents of the encrypted PGP message.

Crypto Weekly: NVIDIA, Coinbase, Standard Chartered and Sui | HODL FM NEWS
NVIDIA acquires Hugging Face, Standard Chartered launches BTC and ETH trading, Coinbase expands derivatives in Canada, and Full Sail shuts down.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.