Liquid Sidechain Paused After 3,998 BTC Leaves Federation Wallet
Blockstream's Liquid sidechain paused operations after nearly its entire bitcoin reserve—approximately 3,998 BTC worth $320 million—was withdrawn from the federation wallet through an authorized key. The recipient of the funds claimed to be white-hat researchers in an on-chain message, though the vulnerability that enabled the withdrawal and the legitimacy of the claim remain unclear.
Why It Matters
This incident highlights critical vulnerabilities in federated bridge designs that secure billions in cross-chain assets. The pause affects one of Bitcoin's established layer-two networks and raises questions about the security assumptions underlying sidechain architectures, particularly when authorized credentials can be exploited despite multisig protection.
Key Facts
- Amount withdrawn: 3,998.5 BTC (approximately $320 million)
- Federation wallet remaining: 197.47 BTC
- Authorization method used: SideSwap PAK (Peg-out Authorization Key)
- Multisig configuration: 11-of-15
- PAK update delay: Three days to change access list
Liquid, Blockstream's sidechain for Bitcoin, halted bridge operations Sunday after an unknown party withdrew nearly all bitcoin reserves backing the network's L-BTC token. The approximately 3,998 BTC exodus moved through the SideSwap Peg-out Authorization Key, one of the federation's authorized withdrawal mechanisms, leaving the federation wallet with only 197.47 BTC remaining. The recipient moved the funds into a single transaction and embedded an on-chain message claiming white-hat status, followed by on-chain communications from a third party providing a Signal contact method.
Blockstream's response indicated the withdrawal occurred through a valid authorization credential rather than a compromised private key. The company disabled bridge nodes to prevent new transaction submissions and instructed exchanges to suspend L-BTC deposits and withdrawals. Other assets issued on Liquid, including USDT and DePix, remained unaffected by the pause. The incident raised immediate questions about how an authorized key could be used to drain the entire bridge reserve despite the network's stated security measures.
Liquid's architecture includes a 3-day delay before updating its Peg-out Authorization Key list—a design feature intended to detect compromised credentials before attackers could withdraw funds to external addresses. The multisig structure requires 11 of 15 functionaries to approve transactions, yet these layers apparently did not prevent the withdrawal. Charles Guillemet, Ledger's chief technology officer, noted the incident's unusual characteristics: the claimants simultaneously demanded ransom-style contact through multiple channels while professing white-hat intentions, a pattern inconsistent with standard responsible disclosure practices.
The vulnerability's precise nature remains undisclosed. Blockstream had published a roadmap in May outlining plans to replace the federated bridge design with a BitVM-style 1-of-n mechanism intended to reduce reliance on the functionary set. That upgrade was not yet implemented when the withdrawal occurred. The pause represents the second major Bitcoin-adjacent network to suspend operations due to security concerns within two weeks, following Core Lightning's decision to take nodes offline in late August.
Keep Reading

Bitcoin’s golden cross is here

Hunter Biden wants to launch a LAPTOP memecoin. Crypto traders hate it already

Bit2Me sets up specialized unit to help law enforcement track down crypto assets
