Liquid Network Halts Operations After $320M Bitcoin Withdrawal by Self-Described White Hats
Key Takeaways
- •Actors claiming to be white-hat hackers withdrew about 4,000 BTC, worth roughly $320 million, from Liquid's federation wallet, representing about 95% of its balance.
- •Liquid disabled its bridge nodes and exchanges halted L-BTC deposits and withdrawals, though other assets on the network such as USDT were unaffected.
- •Blockstream contacted the actors using signed onchain messages, and the actors said they would return the majority of the Bitcoin once the vulnerability was fixed and every node had installed the patch.
- •Samson Mow compiled a timeline of the onchain exchange, noting that Blockstream's reply confirmed the return address but did not necessarily agree to the patching condition.
- •SideSwap stated the withdrawal was processed as a customer peg-out order and that the L-BTC involved originated from a bug in Elements, the open-source software underlying Liquid, rather than a compromise of its systems.

[Update, Sept. 7, 2026, 7:30 UTC: Added correspondence between the “white hats” and Blockstream.]
The Bitcoin sidechain Liquid paused operations after actors claiming to be white-hat hackers withdrew approximately 4,000 Bitcoin — worth $320 million — from the network’s federation wallet.
Liquid, launched by Blockstream in 2018, is a federated sidechain designed to move Bitcoin between exchanges and traders faster than the base layer. Unlike Bitcoin’s mainchain, it does not rely on miners; instead, a consortium of functionaries jointly controls the multisignature wallet that holds the BTC backing L-BTC, meaning the network’s security model rests on that federation rather than on proof of work.
Liquid said on Sunday that bridge nodes had been disabled, preventing new transactions from being processed, while exchanges had halted or were preparing to halt L-BTC deposits and withdrawals. According to the network, other assets issued on Liquid, including USDT, DePix and real-world assets, were unaffected. (X post)
Blockstream, Liquid’s technology provider, established contact with the actors using signed onchain messages. The actors stated they would return the majority of the Bitcoin once the vulnerability had been fixed and every node had installed the patch. As of the time of writing, the funds had not yet been returned. (Onchain transaction)
The withdrawal accounted for roughly 95% of the wallet’s balance of approximately 4,200 BTC. Because Liquid relies on Bitcoin held through its federation to back the L-BTC issued on the sidechain, the majority of the wallet’s BTC remains under the actors’ control until the funds are returned. If the funds are not returned, L-BTC holders could face uncertainty about the backing of their tokens, since each L-BTC in circulation is meant to correspond to BTC locked in the federation wallet.
Cointelegraph reached out to Liquid Network and Blockstream for comment.
Purported white hats negotiate with Blockstream
Samson Mow, CEO of Jan3 and former chief strategy officer at Blockstream, compiled a detailed timeline of the public messages embedded in Bitcoin transactions in an X post.
The exchange began at 11:30 am Pacific time, when the actors identified themselves as white hats and requested onchain contact. Blockstream replied roughly an hour later, directing them to its security email, and subsequently sent a PGP-encrypted message.
Hours afterward, the actors asked whether they could return most of the Bitcoin to a Blockstream address. They then demanded that the vulnerability be fixed and every node updated before transferring the funds.
“Yes, thank you,” Blockstream responded.
According to Mow, that reply answered the return-address question rather than agreeing to the patching condition. Around 3,998.5 BTC remained unmoved at that point, with no further messages recorded as of 9:12 pm Pacific time.
Related: Satoshi-era Bitcoin wakes after 16 years of dormancy as 600 BTC moves
SideSwap said the withdrawal was processed through its peg-out service as a customer order using its Peg-out Authorization Key (PAK), but that the key itself was not compromised. The company stated that the L-BTC used in the transaction originated from a bug in Elements — the open-source software underpinning Liquid — rather than from SideSwap’s systems. (X post)
Magazine: ‘White hats’ take 4000 BTC from Liquid, ETFs see best inflows of 2026: Hodler’s Digest