Bitcoin sidechain Liquid pauses after purported ‘white hats’ withdraw $320M in BTC
Bitcoin's Liquid sidechain suspended operations after actors claiming to be white-hat hackers withdrew approximately 4,000 BTC worth $320 million from its federation wallet, exploiting a vulnerability in the underlying Elements software. The actors pledged to return the majority of the funds once the security flaw is patched and all network nodes are updated, though the Bitcoin remained inaccessible at the time of reporting.

Why It Matters
This incident highlights critical infrastructure risks in Bitcoin's sidechain ecosystem and demonstrates how vulnerabilities in foundational software can jeopardize hundreds of millions in user assets. The pause underscores the centralized federation model's dependency on patching speed and coordination across distributed node operators.
Key Facts
- Amount withdrawn: Approximately 4,000 BTC, roughly 95% of Liquid's federation wallet balance
- USD value at withdrawal: $320 million
- Claimed actor status: White-hat hackers who promised to return funds after patch deployment
- Affected systems: Liquid bridge nodes disabled; L-BTC deposits and withdrawals halted at exchanges
- Vulnerability source: Bug in Elements, the open-source software underlying Liquid
The Liquid sidechain came to an abrupt halt after unknown parties successfully extracted nearly the entirety of its backing Bitcoin reserve through an exploit in Elements software. The withdrawal froze bridge functionality across the network, forcing major exchanges to restrict L-BTC trading activity. Other assets issued on Liquid's infrastructure, including USDT and tokenized real-world assets, continued operating normally as the withdrawal specifically targeted the network's Bitcoin reserves.
The actors behind the extraction initiated contact with Blockstream through signed messages embedded in Bitcoin transactions, establishing themselves as white-hat security researchers rather than malicious thieves. This characterization carries significant weight in cryptocurrency communities, where white-hat designations typically indicate actors who discover vulnerabilities to alert developers rather than exploit them for personal gain. The correspondence, compiled and shared publicly by Jan3 CEO Samson Mow, documented a roughly four-hour negotiation window during Pacific business hours.
Blockstream engaged with the actors through encrypted communications, eventually acknowledging their offer to return the funds contingent on resolving the vulnerability and achieving comprehensive node updates. The security firm's brief affirmative response became the subject of interpretation disputes, with Mow noting potential ambiguity about whether Blockstream was simply confirming the return address or formally accepting the patching condition. At the reporting cutoff, the 4,000 BTC remained in the actors' control.
Investigation into the extraction method revealed the exploit operated through SideSwap's peg-out service, using that platform's authorization infrastructure. SideSwap clarified that its Peg-out Authorization Key had not been compromised, attributing the successful withdrawal to the upstream Elements bug that the actors leveraged. This distinction clarified that the vulnerability existed at Liquid's core software layer rather than through any third-party integration failure.
The incident exposes structural tensions in sidechain security models that depend on federation participants controlling consolidated Bitcoin reserves. Unlike traditional financial systems with redundant safeguards, the federation wallet's near-total depletion demonstrates how a single software vulnerability can render a multi-billion-dollar bridge mechanism inoperable, pending coordinated patching efforts across a distributed node network.
Keep Reading

Bitcoin’s golden cross is here

Hunter Biden wants to launch a LAPTOP memecoin. Crypto traders hate it already

Bit2Me sets up specialized unit to help law enforcement track down crypto assets
