Exchange and Infrastructure Security
Liquid Network Faces Security Scrutiny After Purported White Hats Return $270 Million in Bitcoin
According to reporting by Cointelegraph, actors claiming to be white hats returned approximately $270 million worth of Bitcoin to the Liquid Federation wallet following a recent security incident. This development, which is not officially confirmed by all independent audit bodies, highlights ongoing vulnerabilities in sidechain federation reserves.

Incident Overview and Initial Asset Recovery
According to reporting published by Cointelegraph, a significant security incident involving the Liquid Network resulted in the withdrawal of a substantial amount of cryptocurrency from its federation reserves. The news outlet detailed that actors who identified themselves as white-hat hackers removed approximately 4,000 Bitcoin from the wallet infrastructure, creating immediate operational concerns for the Bitcoin sidechain. These initial withdrawals severely impacted the backing of issued L-BTC tokens, prompting widespread concern across the broader digital asset ecosystem regarding the robustness of federation-controlled peg-out mechanisms.
Subsequent updates provided by Cointelegraph indicated that a large portion of the removed capital was returned to the designated federation wallet addresses following onchain communications. Specifically, the publication noted that roughly 3,400 Bitcoin, valued at approximately $270 million, was transferred back to the infrastructure reserves. This partial restitution represented about 85 percent of the total volume withdrawn during the unauthorized event, bringing a measure of relief to stakeholders monitoring the stability of the pegged assets while technical teams worked to secure the underlying codebase.
Technical Context and Vulnerability Analysis
Reporting from Cointelegraph shed light on the mechanics of the withdrawal, noting that the transaction was processed through SideSwap’s Peg-out Authorization Key. However, both Liquid and SideSwap clarified that the key itself was not compromised during the episode. Instead, SideSwap representatives attributed the underlying L-BTC movement to a software bug residing within Elements, the open-source platform that serves as the technological foundation for the Liquid sidechain infrastructure. This distinction proved crucial for understanding how the breach occurred without a direct private key theft.
In response to the identified vulnerability, Cointelegraph noted that Blockstream initiated direct communication with the actors through cryptographically signed messages embedded inside Bitcoin transactions. The individuals behind the removal stated that they would restore the majority of the funds once the critical vulnerability was fully addressed and every federation node had successfully installed the necessary software patches. This unconventional negotiation channel highlighted the evolving dynamics of incident response within decentralized and federated network environments, where peer-to-peer messaging often substitutes for traditional legal channels.
Outstanding Funds and Industry Skepticism
Despite the substantial recovery of funds, Cointelegraph reported that a notable balance of approximately 598 Bitcoin remained unreturned by the actors. Blockstream leadership confirmed that engagement with the individuals holding the remaining reserves was ongoing, though the exact terms of any potential resolution or bounty agreement remained undisclosed to the public. The presence of this outstanding balance fueled considerable debate among industry security experts regarding the classification of the actors as genuine white hats.
Highlighting the industry skepticism, Cointelegraph cited Ledger Chief Technology Officer Charles Guillemet, who publicly questioned the white-hat designation applied to the participants. Guillemet argued that if the roughly 600 Bitcoin retained by the actors constituted a negotiated bounty or reward arranged through encrypted communications, the arrangement closely resembled extortion rather than standard ethical hacking practices. Neither Blockstream nor Liquid officially characterized the retained amount as a bounty, leaving the precise nature of the financial arrangement ambiguous.
Network Pause and Preparation for Restart
Cointelegraph reported that the Liquid Network was kept in a paused state while Blockstream and various federation members implemented comprehensive security fixes and structural improvements. The technical teams also had to resolve an associated chain split that occurred during the incident response phase. These extensive maintenance measures were deemed essential before any safe network restart could be scheduled, ensuring that the underlying architecture would be fully hardened against similar future vulnerabilities.
During the ongoing operational downtime, JAN3 CEO and former Blockstream executive Samson Mow advised users through Cointelegraph coverage to exercise extreme caution. He explicitly urged network participants to refrain from depositing Bitcoin into Liquid peg-in addresses until an official confirmation of the network restart was broadcast. Furthermore, Mow noted that aside from exercising patience and withholding new deposits, no direct technical action was required from ordinary users during the remediation period.
Assessment of Recovery, Impacts, and Next Steps
In conclusion, Cointelegraph reported that the Liquid Network secured the return of 3,400 Bitcoin, representing 85% of the funds removed in the security incident involving SideSwap’s authorization keys and Elements software. This recovery, which remains not officially confirmed by independent third-party audits, directly affects Liquid Federation members and users relying on L-BTC liquidity. What changes now is that the network remains paused while final patches and chain-split resolutions are applied, and users must halt all peg-in deposits.
The concrete finding of this intelligence report is that the asset return has significantly mitigated reserve losses for the affected entity, Liquid Federation, but leaves nearly 600 Bitcoin unverified in status. The next action for affected users and market participants is to monitor official communication channels from Blockstream and refrain from interacting with peg-in addresses until a verified operational restart is announced. Readers should note that these findings are based on media reporting and remain not officially confirmed by first-party regulatory or judicial bodies.
Cexvia conclusion
Assessment of the Liquid Network Bitcoin Recovery and Operational Restart
Cointelegraph reported that purported white-hat actors returned 3,400 Bitcoin, representing 85% of the funds removed from Liquid’s federation wallet during a security incident. This finding remains not officially confirmed by comprehensive independent audits or direct official statements from all involved technical teams.
- Risk meaning
- The incident demonstrates operational vulnerabilities within sidechain reserve management and federation authorization mechanisms, raising questions about reserve safety and recovery negotiations.
- User action
- Users should refrain from sending Bitcoin to Liquid peg-in addresses until the network restart is officially verified and operational continuity is restored.

