Crypto· Bitcoin

'Purported White-Hat Hackers' Withdraw $320M in Bitcoin From Liquid

Approximately 4,000 BTC worth $320 million was withdrawn from Blockstream's Liquid sidechain federation wallet on Sunday, with the actors identifying themselves as white-hat hackers through on-chain messages. The withdrawal exploited a bug in Elements software rather than a compromised key, and the parties have since engaged in PGP-signed communications negotiating the return of the funds conditional on patching the vulnerability.

By AI NewsroomPublished about 18 hours agoUpdated about 18 hours ago3 views
'Purported White-Hat Hackers' Withdraw $320M in Bitcoin From Liquid

Why It Matters

This incident highlights critical security risks in cryptocurrency bridge infrastructure, where software vulnerabilities rather than key compromises can enable the unauthorized creation and redemption of backed assets. The outcome of negotiations between Blockstream and the hackers will test whether bridge operators can effectively coordinate security fixes while recovering user funds.

Key Facts

  • Amount withdrawn: Approximately 4,000 BTC (~$320 million)
  • Wallet status: Reduced from 4,200 BTC to roughly 200 BTC (5% of original holdings)
  • Root cause: Bug in Elements software, not compromised federation keys
  • Peg-out service used: SideSwap's peg-out authorization key
  • Remaining network impact: Other Liquid assets (USDT, DePix, RWAs) and Bitcoin network unaffected

Blockstream's Liquid sidechain suffered a major security incident Sunday when roughly 4,000 BTC was withdrawn from the federation wallet backing the L-BTC token. The withdrawal, valued at approximately $320 million, reduced the wallet's holdings to around 200 BTC. The parties claiming responsibility identified themselves as white-hat hackers and established communication with Blockstream through PGP-signed messages embedded in Bitcoin transactions.

Unlike typical security breaches, the withdrawal did not result from compromised cryptographic keys. Instead, the incident exploited a software bug in Elements, the underlying protocol Liquid operates on. SideSwap, a federation member managing peg-out services, confirmed that its authorization key remained secure and that no systems were breached. The attackers created L-BTC tokens without corresponding Bitcoin backing, then processed a redemption that appeared legitimate within the system's normal operations. Blockstream had deployed a fix to the underlying software five weeks prior but had not yet implemented it across the network.

Communications between Blockstream and the suspected hackers reveal an unusual negotiation dynamic. The actors offered to return most of the withdrawn funds but attached a condition: Blockstream must patch the vulnerability and update every network node before the funds are returned. Blockstream responded affirmatively to both the offer and the condition within the same blockchain block. This exchange has generated debate within the security community about whether such behavior aligns with legitimate white-hat practices, with some industry figures noting parallels to previous bridge exploits like Ronin and Euler.

The incident demonstrates the sophisticated attack vectors facing multi-signature bridge infrastructure. While the hack isolated impact to Liquid's L-BTC mechanism, other assets on the sidechain including USDT and tokenized real-world assets remained untouched. Bitcoin's main network experienced no disruption. The resolution of ongoing negotiations between Blockstream and the hackers will likely influence how bridge operators approach vulnerability disclosure and fund recovery processes in decentralized finance.

Keep Reading