Alleged White-Hat Hackers Withdraw 4,000 Bitcoin From Blockstream's Liquid Network Federation Reserves
Key Takeaways
- •Purported white-hat hackers withdrew 4,019.4 BTC, worth roughly $320 million, from the Liquid Network federation treasury backing L-BTC.
- •The attackers appear to have exploited an inflation bug on the LBTC sidechain to create fraudulent tokens and cash them out for on-chain bitcoin, which the federation's HSM servers signed as valid.
- •Bridge nodes on the Liquid Network were paused and exchanges were told to halt L-BTC deposits and withdrawals, while other issued assets such as USDT were unaffected.
- •The hackers left an on-chain message stating they are white hats and asking to be contacted, with the stolen funds remaining at a publicly watchable address at the time of writing.
- •The treasury held over 4,200 BTC before the breach but was left with a little over 207 BTC afterward, leaving LBTC holders' funds effectively at risk.

The Liquid Network said Sunday that purported white-hat hackers withdrew about 4,000 bitcoin, worth roughly $320 million, from the federation wallet that backs L-BTC. Bridge nodes were disabled and the sidechain was paused, while other issued assets — including USDT, DePix and RWAs — were unaffected, the official account said on X. The incident is one of the largest known losses tied to a Bitcoin sidechain, and it draws renewed attention to the security trade-offs of federated bridges, where trust is placed in a consortium of functionaries rather than in a public proof-of-reserve mechanism enforced by the Bitcoin base layer itself.
The Liquid Network is a federated Bitcoin sidechain founded by Adam Back's Blockstream and launched in 2018. It issues a variety of assets, such as LBTC, which are backed by BTC on the Bitcoin main chain, held in a large multisig of 15 known corporate members, including exchanges and infrastructure firms. Eleven of the 15 members must sign a valid multi-signature transaction to move coins from the treasury. Tether also issues USDT on Liquid, which is why the network's other issued assets were a point of concern for holders this week. Before the hack, the treasury held over 4,200 BTC; afterward, Blockstream's proof of reserves page reported a little over 207 BTC remaining.
The hackers withdrew 4,019.4 BTC from the reserve address in a peg-out transaction using the SideSwap Peg-out Authorization Key, visible on mempool.space. SideSwap is a bridge exchange and a member of the Liquid Federation. While the mechanism of the hack has not been confirmed, it appears the attackers exploited an inflation bug on the LBTC sidechain to create more than 4,000 LBTC that did not previously exist, then cashed them out for on-chain bitcoin from the federation. Because the transaction appeared valid under the consensus bug, the federation members' HSM security servers signed the BTC withdrawal transaction, worth roughly $320 million at the time. Notably, the hardware signing devices performed as designed — the vulnerability, if confirmed, would lie in the sidechain's consensus rules, which validated the fraudulent LBTC as legitimate.
The hacker moved the funds to an address ending in 6gyqjlte, from which they quickly signed a new transaction with a message in the OP_RETURN arbitrary data field reading "we are whitehats. contact us on chain." Those coins remained at that address at the time of writing.
A small mainnet transaction to the hacker address followed, carrying an OP_RETURN message saying "Please contact security@blockstream.com" — presumably from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried "Please contact us on Signal @m671aw.70"; however, this may be spam, as it does not share a link to the address holding the stolen funds.
In response to the breach, exchanges were told to pause L-BTC deposits and withdrawals. Bridge nodes on the Liquid Network have been paused, limiting access to the sidechain, which continues to produce blocks.
JAN3 CEO Samson Mow said on X that Aqua's Liquid features were affected and that on-chain bitcoin still worked. Other industry wallets using the Liquid Network are expected to be affected as well. Users holding LBTC now effectively have their savings at risk, since the underlying BTC is currently not redeemable.
Given the private nature of the Liquid chain, on-chain analytics on user holdings are scarce, and little public information exists about how much LBTC is held by retail users versus corporations or Blockstream itself. Should the funds not be returned, it would be a heavy blow to the Liquid Network's user base and to the broader federated sidechain model, which depends on user confidence that pegged reserves are intact. LBTC holders have few options but to wait for conversations with the hackers to resolve. Given the scale of the theft, it would be difficult — though perhaps not impossible — for the hackers to get away with all that bitcoin, as the stolen funds sit at a publicly watchable address and any attempt to move them through regulated services would attract scrutiny. One possible outcome is that the hackers request a finder's fee and return the majority of the funds.
This post first appeared on Bitcoin Magazine and is written by Juan Galt.