Blockchain AcademicsBlockchain Academics
Liquid Network Paused After $320 Million Bitcoin Withdrawal; White-Hat Claim Follows

Liquid Network Paused After $320 Million Bitcoin Withdrawal; White-Hat Claim Follows

Blockstream's Liquid Network sidechain went dark on Sunday after an unknown party drained approximately $320 million in bitcoin from the protocol's peg, leaving an on-chain message claiming white-hat intent and triggering an immediate halt across the network.

Alejandro Silva RamírezEdited by Wael RajabSeptember 6, 20266 min read
Share

Liquid Network Paused After $320 Million Bitcoin Withdrawal; White-Hat Claim Follows

Blockstream's Liquid Network sidechain went dark on Sunday after an unknown party drained approximately $320 million in bitcoin from the protocol's peg, leaving an on-chain message claiming white-hat intent and triggering an immediate halt across the network.

Exchanges suspended LBTC (Liquid Bitcoin, the sidechain's native pegged asset) deposits and withdrawals as Blockstream moved to contain the situation and identify those responsible. The company confirmed it is actively attempting to contact the parties behind the withdrawal. Critically, on-chain data shows the peg still balances, meaning the ratio of locked bitcoin to circulating LBTC has not been broken. That single data point carries outsized weight right now: it is the primary reason this incident looks more like a forced vulnerability disclosure than an outright theft.

Liquid is a federated sidechain, meaning a consortium of trusted functionaries, primarily exchanges and financial institutions, collectively control the peg mechanism that locks bitcoin on the main chain and mints LBTC on the sidechain. A balanced peg after a $320 million withdrawal suggests the funds moved through the protocol's own logic rather than being conjured from thin air. If someone had exploited a minting bug to create unbacked LBTC and then redeemed it for real bitcoin, the peg would show a deficit. It does not. That narrows the likely scenario considerably.

The white-hat claim follows a pattern established in decentralized finance. Protocols including Euler Finance and Curve Finance have previously seen actors drain funds through vulnerabilities, leave on-chain messages asserting benign intent, and later negotiate returns or bounties. The on-chain note left by Sunday's actors fits that template. Whether the claim holds up depends on what Blockstream's investigation reveals about the withdrawal mechanism: was this an authorized path through the federation, an undisclosed vulnerability in the peg contract, or something else entirely? None of those answers are public yet.

What is already clear is the scale of confidence damage. $320 million represents a substantial portion of Liquid's total value locked, and a full network pause, however well-designed as a safety mechanism, signals to institutional users that the sidechain's operational continuity is not guaranteed under stress. Liquid has historically positioned itself as the Bitcoin-native infrastructure layer for exchanges, OTC desks, and asset issuers who need faster settlement and confidential transactions without moving to a separate blockchain entirely. A prolonged pause undercuts that pitch directly.

The on-chain message introduces ambiguity that cuts both ways. A genuine white-hat actor would typically coordinate privately with a protocol's security team before executing a public withdrawal of this magnitude. Draining $320 million first and leaving a note second is an aggressive approach that some security researchers defend as the only way to force a response from slow-moving organizations, but it also creates legal exposure and market disruption that a coordinated disclosure would avoid. The possibility that the message is a social engineering tactic designed to soften regulatory and legal consequences cannot be dismissed.

Blockstream has not published a post-mortem or confirmed the nature of the vulnerability. Until the company provides a technical accounting of how $320 million moved out of the peg in a single event, the market is left weighing two competing readings: a protocol that caught a critical flaw before malicious actors could exploit it, or a protocol that just demonstrated it can be drained at scale. The balanced peg is reassuring. The silence is not.

Update: September 7, 06:41 UTC

The hackers behind the $320 million Liquid Network exploit have conditionally offered to return "most" of the approximately 4,000 BTC they withdrew, according to U.Today and CryptoPoтato. The return is contingent on Blockstream fixing the underlying Elements vulnerability and ensuring all network nodes are patched, CoinTelegraph reports. This development suggests the actors may indeed be operating under white-hat intentions, as initially claimed.

Update: September 7, 07:01 UTC

The hackers have now proposed a conditional resolution: they will return most of the stolen 4,000 BTC once Blockstream patches the underlying Elements vulnerability across all Liquid Network nodes. According to U.Today, CryptoPotato, and CoinTelegraph, the actors are demanding that the network fully remediate the security flaw before they return the funds. This represents a significant development from the initial incident, establishing a potential path toward recovery contingent on fixing the exploit.

Update: September 7, 07:22 UTC

The purported white-hat hackers have now offered to return "most" of the ~4,000 BTC withdrawn from Liquid Network, contingent on specific conditions. According to U.Today and CoinTelegraph, the attackers will only return the funds after Blockstream patches the Elements vulnerability across all nodes on the network. CryptoPotato reports the hackers demanded the bug be fixed and every node patched before they would initiate the return.

Update: September 7, 07:41 UTC

The hackers who withdrew nearly 4,000 BTC from Liquid Network have now offered conditional terms for returning the funds. According to U.Today, they will return "most" of the stolen bitcoin only after Blockstream addresses the underlying vulnerability and patches every node on the network. CryptoPotato reports the alleged white-hat hacker explicitly demanded that Liquid fix its bug and complete a full node update before any restitution occurs, suggesting they view the exploit as leverage to force security improvements.

Update: September 7, 08:03 UTC

The purported white-hat hackers have offered conditional return of the ~4,000 BTC stolen from Liquid Network. According to U.Today, the attackers will return "most" of the funds only after Blockstream patches the Elements vulnerability across all nodes. CryptoPotato reports the hackers specified that Liquid must fix the bug and patch every node before any funds are returned, while CoinTelegraph confirms the actors communicated this condition directly to Blockstream.

Update: September 7, 09:37 UTC

The hackers have now laid out conditions for returning the stolen funds. According to U.Today and CryptoPotato, they will return "most" of the nearly 4,000 BTC only after Blockstream patches the vulnerability across every node on the network. This conditional offer suggests the attackers are attempting to incentivize rapid security improvements rather than an immediate return of the withdrawn bitcoin.

Update: September 7, 10:04 UTC

The hackers behind the Liquid Network breach have proposed conditional terms for returning the stolen funds. According to U.Today, they offered to return "most" of the nearly 4,000 BTC on the condition that Blockstream fixes the underlying vulnerability and patches all network nodes before the return occurs. CryptoPotato reports the alleged white-hat hacker emphasized that these security measures must be completed prior to any fund restitution.

Update: September 8, 07:01 UTC

Following the network pause from the $320 million exploit, recovery efforts have progressed with 3,400 BTC returned to the federation wallet after Blockstream confirmed that patched bridge nodes resolved the vulnerability, according to Crypto Daily. However, approximately 598.5 BTC remain outstanding from the original theft.

The incident has exposed fundamental weaknesses in Bitcoin sidechains' federated security models. Crypto Briefing notes the hack raises questions about the trustworthiness of such architectures and has intensified scrutiny around open-source security practices in cryptocurrency infrastructure.

Update: September 8, 07:21 UTC

Following Blockstream's confirmation of patched bridge nodes, the Liquid Network exploit actors have returned 3,400 BTC to the federation wallet, according to Crypto Daily. Approximately 598.5 BTC remains unrecovered from the initial $320 million theft.

The incident has intensified scrutiny of Bitcoin sidechains and federated security models. Crypto Briefing reports the hack exposes vulnerabilities that challenge trust in these systems and raises concerns about open-source security practices in blockchain infrastructure.

Discussion

Loading comments...