A whitehat hacker is holding $320 million in drained Bitcoin until developers prove they patched a fatal network flaw
Image by CryptoSlate

A whitehat hacker is holding $320 million in drained Bitcoin until developers prove they patched a fatal network flaw

SideSwap says bug-created L-BTC passed a valid peg-out flow, prompting federation signers to release about 3,996 real BTC.

Quick Take

  1. A bug-created batch of 4,000 L-BTC passed SideSwap’s authorization, prompting Liquid’s federation to release roughly 3,996 BTC.
  2. The incident halted Liquid’s bridge activity and exposed how valid keys and multiple signers can approve withdrawals lacking underlying Bitcoin backing.
  3. Recovery depends on patching every affected node, returning funds, and proving reserves again match legitimate outstanding L-BTC one-for-one.

Liquid Network was effectively halted after nearly $320 million in Bitcoin left its federation reserve through an abnormal peg-out.

The incident began Sept. 6 when a customer submitted 4,000 L-BTC to SideSwap’s peg-out service, which converts Bitcoin represented on Liquid back into BTC on the main network.

SideSwap said the request passed the normal authorization process and prompted the Liquid Federation to release about 3,996 BTC. The Bitcoin later moved to an address that held roughly 3,998.5 BTC at the latest check.

Liquid disabled its bridge nodes after the withdrawal, while SideSwap suspended swaps, peg-ins, and peg-outs. Exchanges also paused or prepared to pause L-BTC deposits and withdrawals as operators investigated the incident.

The actors controlling the Bitcoin subsequently identified themselves through on-chain messages as “whitehats” and said they intended to return most of the funds once the underlying bug had been fixed across the network.

Related Reading

Blockstream enables smart contract programmability on Bitcoin via Simplicity on Liquid Network

That prospect could limit the eventual financial loss. However, it does not resolve the more important question of how almost 4,000 BTC left the federation without an apparent key compromise.

The withdrawal appears to have followed the rules

Liquid and SideSwap say the incident did not involve stolen signing credentials.

The withdrawal used SideSwap’s valid Peg-out Authorization Key, or PAK, and Liquid said neither that key nor other federation keys were compromised.

Instead, SideSwap said Blockstream traced the 4,000 L-BTC presented for redemption to a flaw in Elements, the software underlying Liquid.

If that explanation is confirmed, the problem occurred before the Bitcoin transaction was signed.

Liquid is designed to maintain one BTC in its federation reserve for every L-BTC in circulation. During a normal peg-out, L-BTC is burned, and an equivalent amount of Bitcoin is released.

Timeline showing Liquid’s 4,000 L-BTC peg-out, 3,996 BTC payout, later 3,998.5 BTC movement, pause status and restart requirements.

In this case, SideSwap says a software bug created L-BTC without corresponding Bitcoin backing. Those tokens nevertheless entered a valid peg-out process, after which federation functionaries treated the withdrawal as legitimate and released real BTC.

Blockchain security firm Bitslab said at least 11 of Liquid’s 15 functionaries ultimately signed the transaction.

That points to a different type of failure from a conventional bridge exploit. Secure keys provide limited protection if every signer is presented with the same invalid state and accepts it as legitimate.

No independent technical postmortem or detailed patch description was public at the latest check, leaving the precise cause attributed to Liquid and SideSwap.

Whitehats want the bug fixed before returning Bitcoin

Meanwhile, the actors holding the funds have been communicating with Blockstream through Bitcoin transactions carrying OP_RETURN messages.

Galaxy Digital research head Alex Thorn said Blockstream first sent a message asking the holder to contact its security team. The holder later responded that it planned to send “most” of the Bitcoin back to the federation.

Liquid Network White hat Hackers Communications With Blockstream
Liquid Network White-Hat Hackers On-Chain Messages With Blockstream (Source: Galaxy Digital)

A subsequent message added a condition that Blockstream should fix the bug first and ensure every node is patched before returning the funds.

That puts Liquid’s next steps beyond simply recovering the Bitcoin.

The federation must identify and remediate the Elements flaw, distribute the fix across affected nodes, and establish that another batch of invalid L-BTC cannot pass through the same authorization process.

It must also reconcile the reserve.

The allegedly bug-created L-BTC was burned during the peg-out, but about 3,996 real BTC still left Liquid’s federation wallet. Until those funds return or the accounting is otherwise restored, the network still has to demonstrate that legitimate outstanding L-BTC remains backed one-for-one.

Liquid’s bridge nodes remain disabled while that work continues.

While the incident may ultimately end with most of the Bitcoin recovered, the harder task is proving that the system which authorized its release cannot make the same mistake twice.

Market Signal Market Signal is a price-based 0–100 indicator combining multi-period momentum, historical range, milestone recency, and volume confirmation. It describes current conditions and is not a price forecast. Bullish 70 / 100
$79,395.19 Down 0.74% over 24 hours
1H Up 0.02% 24H Down 0.74% 7D Up 1.20%
30D Up 22.18% 60D Up 26.31% 90D Up 26.74%

Bitcoin is -0.74% over the past 24 hours and currently sits at rank #1 by market cap.

Market cap $1.59T
Volume (24h) $22.9B Up 14.13%
Circ. supply 20.08M
FDV $1.67T
Loading price history…
Article context

Mentioned in this article

Related Asset Bitcoin #1 BTC $79,395.19 24-hour change: down 0.74% Loading price history… 24H Down 0.74% 7D Up 1.20% 30D Up 22.18% Related Company Blockstream Blockchain technology company