- Liquid Network lost roughly 4,000 BTC, worth $320M, about 95% of its reserves.
- Attackers claimed white-hat status, but the 4,000 BTC return remains unconfirmed.
- The incident highlighted risks tied to sidechain software bugs rather than Bitcoin itself.
A $320 million Bitcoin heist involving roughly 4,000 BTC has placed Liquid Network’s security model under scrutiny after the attackers claimed they were acting as “white hats.” Liquid paused activity after the withdrawal removed about 95% of the Bitcoin held in its federation wallet.
The attackers later left an on-chain message telling Liquid to “contact us on chain,” but no independent confirmation has established that they acted as ethical hackers rather than thieves.
Liquid, launched by Blockstream in 2018, uses a federation of more than 80 exchanges, infrastructure companies and asset managers. The sidechain allows users to lock BTC and receive L-BTC, which supports faster settlement than transactions conducted directly on Bitcoin’s base layer.
$320M Bitcoin Heist Centers on Elements Software Bug
Early technical findings linked the incident to a software flaw in Liquid’s underlying Elements framework rather than stolen private keys.
The funds moved through SideSwap using approved Peg-out Authorization Key infrastructure. Blockstream said no cryptographic keys or hardware modules were compromised. Reports also tied the exploit to an Elements range-proof cache issue that created faulty Bitcoin-linked assets. SideSwap could not distinguish those assets from legitimate coins and processed them under the same system.
Liquid disabled bridge nodes and halted new sidechain transactions while federation members worked on a fix. Exchanges also suspended L-BTC deposits and withdrawals.
White-Hat Claim Unverified as Attackers Demand Network Patch
The attackers embedded the message “we are whitehats. contact us on chain” in the transaction.
They later told developers to patch every affected node before the funds would be returned. The message said the chain remained at risk with the latest software version and promised repayment once the fix was confirmed.
Liquid Exploit Highlights BTC Custody and Sidechain Risk
The incident did not compromise Bitcoin’s underlying blockchain. Instead, it affected the infrastructure built around BTC. Liquid relies on a federated custody model in which Bitcoin remains locked while L-BTC circulates on the sidechain. That structure creates additional dependence on federation controls, bridge software, and transaction-processing systems.
Wrapped BTC models introduce similar additional layers. Centralized products depend on custodians, decentralized bridges depend on code and node networks, while federated sidechains depend on multisignature governance.
The exploit underscores how risks in Bitcoin markets increasingly stem from the layers built around the asset rather than the base protocol itself. As sidechains and custodial frameworks expand functionality, they also introduce new points of failure that can carry significant financial consequences.
Related: THORChain Hit by Over $10M Exploit Across Bitcoin, Ethereum, and Base
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.