Exchange Risk & Security
Purported White-Hat Hackers Withdraw $320M in Bitcoin From Liquid Network
According to media reporting by Decrypt, roughly 4,000 Bitcoin valued at approximately $320 million left the federation wallet backing the Liquid sidechain following an incident involving an Elements software bug and subsequent on-chain negotiations, though these claims remain not officially confirmed.

Incident Overview and Federation Wallet Depletion
Recent media reporting published by Decrypt details a major security incident affecting the Liquid sidechain network, during which a substantial volume of Bitcoin left the central federation wallet. According to the published coverage, approximately 4,000 Bitcoin, valued at roughly $320 million, exited the reserve wallet that backs every circulated L-BTC token within the ecosystem. The reporting outlines that federation members and infrastructure operators scrambled to respond as bridge nodes were disabled over the weekend following the unexpected outflow of funds from the primary multi-signature reserve.
Further details provided in the coverage indicate that the reserve wallet experienced a dramatic reduction in its holdings, dropping from an initial balance of around 4,200 Bitcoin down to roughly 200 Bitcoin remaining inside the vault. Observers noted that the outflow did not involve forceful breaches of standard administrative keys, but rather unfolded through ordinary-looking peg-out transactions that utilized valid authorizations. Industry commentators and security analysts quickly focused their attention on the mechanics of the outflow, noting the stark contrast between the previous reserve depth and the remaining balance after the weekend operations concluded.
Technical Vector and Elements Software Vulnerability
According to the media reports, the mechanism behind the outflow relied on the creation of synthetic L-BTC units that lacked proper underlying Bitcoin backing before being cashed out through standard redemption channels. SideSwap, a federation member operating a peg-out service, stated that a customer submitted a large volume of L-BTC, which was subsequently burned under valid authorization parameters, leading the federation to disburse thousands of Bitcoin shortly thereafter. Both Liquid representatives and SideSwap emphasized that neither the peg-out keys nor any other administrative credentials were compromised during the operational sequence.
Instead, the reporting points toward a software vulnerability within Elements, the underlying codebase upon which the Liquid sidechain operates. While Blockstream did not immediately publish a comprehensive technical breakdown of the bug in the initial reporting coverage, industry insiders noted that a software patch addressing the underlying code flaw had been introduced into the repository weeks prior to the incident. Security experts continue to debate the exact nature of the vulnerability and whether sufficient node updates had been deployed across the decentralized federation network before the exploit window was leveraged by external actors.
On-Chain Negotiations and PGP-Signed Communications
Following the sudden depletion of the federation reserve, the parties involved engaged in a highly unconventional series of communications directly through the Bitcoin blockchain. The entity responsible for the withdrawal left an immutable on-chain message stating that they operated as white-hat actors and invited the development team to establish contact via transaction data fields. Blockstream responded within an hour by providing an official email address, which initiated a multi-step dialogue conducted through PGP-signed messages embedded directly inside subsequent Bitcoin transactions.
During these transparent negotiations, the purported white-hat hackers expressed willingness to return the majority of the intercepted coins, but attached a strict operational condition requiring the development team to patch the underlying bug and ensure all federation nodes updated their software. Blockstream acknowledged the communication and confirmed the patch condition within the block structure. Prominent security figures and industry executives, including Ledger chief technology officer Charles Guillemet and former Blockstream security chief Samson Mow, publicly scrutinized the exchange, debating the evolving definition of white-hat behavior in modern decentralized finance security incidents.
Ecosystem Impact and Unaffected Asset Classes
Despite the severity of the reserve drain affecting the Liquid network, independent media reporting confirms that other digital assets hosted on the sidechain infrastructure remained entirely secure and untouched throughout the episode. Tokens such as USDT, DePix, and various tokenized real-world assets circulating within the Liquid environment experienced no direct operational disruption or balance loss. Furthermore, commentators emphasized that the primary Bitcoin mainnet network operated normally without any consensus disruptions, isolation, or performance degradation resulting from the sidechain security event.
The containment of the impact to the specific federation reserve wallet and L-BTC bridging mechanism prevented a systemic contagion across broader cryptocurrency markets, though market participants remained vigilant regarding sidechain governance and bridge architecture safety. Observers noted that while secondary tokens on Liquid avoided direct loss, the temporary suspension of federation bridge nodes created immediate liquidity bottlenecks for traders attempting to move assets between the Bitcoin main layer and the Liquid sidechain environment while developers worked to resolve the vulnerability.
Conclusion, Finding, and Required Actions
In conclusion, media reporting from Decrypt establishes that roughly 4,000 Bitcoin valued at $320 million were withdrawn from the Liquid Federation reserve via SideSwap peg-out keys following an Elements software bug, though these claims remain not officially confirmed. The affected entity is Blockstream and the Liquid network, while the primary user group impacted consists of L-BTC holders and sidechain liquidity providers. What changes now is that federation nodes must enforce strict software updates and patch verifications before bridge operations resume, and users must acknowledge that bridging services remain temporarily paused.
The concrete finding of this risk intelligence report is that while on-chain communications between Blockstream and purported white-hat hackers suggest a potential return of funds conditional upon software patching, the entire sequence relies entirely on media reporting that remains not officially confirmed by first-party forensic audits. The next action for participants is to monitor official Blockstream announcements for confirmed bridge restoration timelines, verify that node software is updated to the latest secure commit, and refrain from attempting cross-chain transactions until operational safety is fully restored across the network.
Cexvia conclusion
Conclusion and Operational Outlook
Media reporting by Decrypt indicates that approximately 4,000 Bitcoin were withdrawn from the Liquid Federation wallet via SideSwap's peg-out key in an event involving purported white-hat hackers, a development that affects Liquid network users and involves ongoing communications, though these accounts remain not officially confirmed.
- Risk meaning
- The incident demonstrates how underlying codebase vulnerabilities in sidechain federation infrastructure can be leveraged to mint and redeem unbacked synthetic tokens, highlighting critical risks for cross-chain bridge security and federation wallet management.
- User action
- Users interacting with the Liquid network and its issued assets should monitor official communications from Blockstream, pause bridging activities until node software patches are verified, and review exposure to synthetic assets on sidechain environments.

