A $320 million Bitcoin heist involving roughly 4,000 BTC has placed Liquid Network’s security model under scrutiny after the attackers claimed they were acting as “white hats.” Liquid paused activity after the withdrawal removed about 95% of the Bitcoin held in its federation wallet.
The attackers later left an on-chain message telling Liquid to “contact us on chain,” but no independent confirmation has established that they acted as ethical hackers rather than thieves.
Liquid, launched by Blockstream in 2018, uses a federation of more than 80 exchanges, infrastructure companies and asset managers. The sidechain allows users to lock BTC and receive L-BTC, which supports faster settlement than transactions conducted directly on Bitcoin’s base layer.
Early technical findings linked the incident to a software flaw in Liquid’s underlying Elements framework rather than stolen private keys.
The funds moved through SideSwap using approved Peg-out Authorization Key infrastructure. Blockstream said no cryptographic keys or hardware modules were compromised. Reports also tied the exploit to an Elements range-proof cache issue that created faulty Bitcoin-linked assets. SideSwap could not distinguish those assets from legitimate coins and processed them under the same system.
The attackers embedded the message “we are whitehats. contact us on chain” in the transaction.
They later told developers to patch every affected node before the funds would be returned. The message said the chain remained at risk with the latest software version and promised repayment once the fix was confirmed.
(adsbygoogle = window.adsbygoogle || []).push({});The incident did not compromise Bitcoin’s underlying blockchain. Instead, it affected the infrastructure built around BTC. Liquid relies on a federated custody model in which Bitcoin remains locked while L-BTC circulates on the sidechain. That structure creates additional dependence on federation controls, bridge software, and transaction-processing systems.
Wrapped BTC models introduce similar additional layers. Centralized products depend on custodians, decentralized bridges depend on code and node networks, while federated sidechains depend on multisignature governance.
The exploit underscores how risks in Bitcoin markets increasingly stem from the layers built around the asset rather than the base protocol itself. As sidechains and custodial frameworks expand functionality, they also introduce new points of failure that can carry significant financial consequences.
