Key Takeaways
- Approximately 4,000 BTC valued at $320 million was extracted from Liquid Network’s federation wallet by individuals claiming to be ethical hackers
- The vulnerability originated from a code flaw in Elements, the open-source framework underlying Liquid, rather than from compromised cryptographic keys
- The extraction occurred via SideSwap, an authorized trading interface, which complicated early detection efforts
- The individuals responsible are engaging with Blockstream through blockchain-based Bitcoin messages and have pledged to restore the assets following vulnerability remediation
- Additional digital assets on the platform, including USDT, remained unaffected by the incident
Liquid Network, a Bitcoin layer-2 solution utilized by cryptocurrency exchanges for accelerated transaction settlement, has suspended all network activity following the extraction of approximately $320 million in Bitcoin by actors identifying themselves as ethical security researchers.
The security breach occurred on Sunday, September 7, when individuals claiming white-hat status removed roughly 4,000 of the 4,200 Bitcoin stored within Liquid’s federated custody system. This represents approximately 95% of the network’s entire Bitcoin reserves.
Understanding Liquid Network
Blockstream introduced Liquid Network in 2018 as a Bitcoin sidechain solution engineered to enable cryptocurrency exchanges to execute settlements more rapidly than the primary Bitcoin blockchain permits.
The platform generates L-BTC tokens, which maintain a 1:1 peg with actual Bitcoin secured in a federated wallet structure. This federation comprises over 80 participating entities, including cryptocurrency exchanges, blockchain infrastructure providers, and institutional asset management firms.
The extraction of nearly the complete reserve has sparked significant concerns regarding the security architecture of this settlement framework.
Technical Details of the Security Breach
Unlike most cryptocurrency security incidents this year, this breach did not result from credential theft or private key compromise.
Rather, a critical vulnerability in Elements—the open-source codebase powering Liquid—enabled the generation of Bitcoin units without proper backing. These improperly created assets were subsequently transferred through SideSwap, a legitimate and authorized trading interface operating on the network.
SideSwap representatives confirmed their Peg-out Authorization Key remained secure and uncompromised. The platform stated it lacked the capability to distinguish between legitimately backed coins and those generated through the vulnerability, resulting in uniform processing of all withdrawal requests.
Cybersecurity experts have identified the vulnerability as existing within the node-level transaction processing software of Liquid, distinct from hardware security modules or cryptographic key management infrastructure.
The individuals responsible have transmitted blockchain-inscribed Bitcoin messages directly to Blockstream. One communication stated: “Please fix the bug first. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
According to Galaxy Digital’s head of research, Alex Thorn, the hackers have also transmitted encrypted technical documentation to Blockstream to facilitate identification and remediation of the security flaw.
As of this publication, the extracted Bitcoin remains unreturned and the network continues to operate under suspension. Bridge node infrastructure has been deactivated, and participating exchanges have either suspended or initiated procedures to halt L-BTC deposit and withdrawal functionality.
Liquid representatives confirmed that alternative digital assets hosted on the network, including Tether (USDT), DePix, and tokenized real-world assets, experienced no impact from this incident.
This security event arrives just days after a $6 million exploit targeting a decentralized lending protocol associated with Crypto.com, and follows earlier security incidents involving Coldcard hardware wallet devices. Blockstream has not disclosed a projected timeline for network restoration.



