‘Good’ Hackers Stole $320 Million in Bitcoin From Liquid, Then Returned Most of It After Blockstream Patched the Bug

Liquid lost 4,000 BTC to alleged white-hat hackers, who have now returned 3,400 BTC after Blockstream patched the vulnerability and secured the network.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

$320 million in Bitcoin just vanished from one of the industry's most trusted and leading networks, Liquid, developed by Blockstream. Around 4,000 BTC — that's 95% of its entire holdings — was withdrawn from Liquid’s federation wallet by what it cautiously described as "purported white-hat hackers." [1]

And the highlight? Those who took it claimed that they stole it to help, rather than to steal the funds. The attackers said they’d return the Bitcoin, and made good on there promise to the tune of 3,400 BTC so far. However, around 598.5 BTC, worth roughly $47 million, remains in their wallet.[2]

Interestingly, neither the SideSwap PAK nor any other PAK appeared to have been compromised. If you hold LBTC, use SideSwap, or transact on any Bitcoin sidechain, this incident should raise an important question: how much are you willing to leave on the table?

With Liquid effectively paused and LBTC deposits and withdrawals suspended, users now have to wait for the network to resolve the issue before they can move their funds. The network is still undergoing security work and preparing for a safe restart.

Here's everything you need to know about this crypto heist and what you can do to stay safe.

In this article
How hackers drained Liquid’s Bitcoin
The hackers return most of the stolen Bitcoin
Why Bitcoin sidechains carry different risks
What can you do to protect yourself
Bottom line

How hackers drained Liquid’s Bitcoin

Liquid works by pegging Bitcoin in and out of the sidechain. When you send real Bitcoin to the Liquid Federation (peg-in), you get LBTC (Liquid's Bitcoin-equivalent token) in exchange, which can then be used for transactions on the sidechain.

Next, you can send your LBTC back and receive your actual Bitcoin. This is known as pegging out. However, since pegging out releases real Bitcoin, not everyone can initiate the process.

Entities that are allowed to peg out have to register a public key in advance, which is known as a Peg-out Authorization Key (PAK). Whenever an entity requests a peg-out, it has to be verified against this PAK.

The funds were moved through SideSwap, a third-party trading and wallet app built on top of the Liquid Network, using the SideSwap PAK. But what's shocking is that neither SideSwap's key nor any other PAK appears to have been compromised in this attack.

According to SideSwap, the LBTC involved in the transaction was created through a bug in the Elements software, which Liquid is built on. SideSwap also said that neither its systems nor its peg-out authorization key had been compromised.

In other words, the issue appears to have been with the creation of the LBTC itself rather than a compromised PAK or SideSwap system. The newly created LBTC could then be sent through the regular peg-out process, resulting in the Liquid Federation paying out real Bitcoin.

The hackers return most of the stolen Bitcoin

The attackers initially claimed to be "white-hat" attackers, meaning that they stole the Bitcoin to demonstrate the underlying vulnerability in Liquid's infrastructure and asked Blockstream to get in touch. Blockstream provided its security team's contact details, and the communications have now been said to have moved to encrypted channels.

The on-chain message from the attackers asked the team to fix the bug first. The message said, "The chain is under risk at latest commit right now. Make sure every node is patched, then we will transfer the money back safely after confirming the fix."

Blockstream later confirmed that its bridge nodes had been patched and told the attackers it was "safe to return the funds." Shortly afterward, the attackers returned 3,400 BTC to the federation address, leaving around 598.5 BTC in their wallet.

That means around 85% of the Bitcoin has now been recovered, but roughly $47 million worth remains outstanding. The attackers have not returned the remaining funds, and it’s unclear whether they intend to do so.

Liquid Network informed users about the incident through a post on X and said that exchanges have already been notified and all LBTC deposits and withdrawals have been paused.

Bridge nodes have been temporarily disabled, so no new transactions can be submitted to the network. The Liquid sidechain remains effectively paused while Blockstream and Federation members make additional fixes and security improvements, resolve a chain split, and prepare for a safe restart.

However, other Liquid assets such as USDT, RWAs, and DePix have not been affected.

Why Bitcoin sidechains carry different risks

The incident fits into a well-established pattern in the crypto industry — cross-chain bridges and pegged asset systems have been among the most vulnerable and have led to large crypto losses over the years.

  • For instance, in March 2022, the Ronin Network, an Ethereum sidechain built for the Axie Infinity game, lost roughly $625 million to North Korea's Lazarus Group after attackers were able to steal private keys and generate fake withdrawals.
  • Similarly, in February 2022, the Wormhole Bridge, which moves assets between Solana and Ethereum, lost $325 million after attackers were able to exploit weaknesses in the protocol's validation system.
  • In August 2022, the Nomad Bridge lost $190 million due to a bug that allowed users to withdraw more funds than what they had deposited.

None of these losses were attributed to Bitcoin or Ethereum's underlying security failure, but rather to the bridge or federation layer sitting on top of these chains. This underlines the fact that bridges built on the base-layer blockchain don't inherit the same level of security as Bitcoin or Ethereum.

For example, Bitcoin's base layer is secured by proof of work and thousands of independent miners. However, when you move to a sidechain, you’re not trusting the base network but only a specific set of instructions, code, and a fixed group of functionaries.

What can you do to protect yourself

Although the attackers have now returned most of the stolen Bitcoin, there’s no guarantee that all the remaining funds will come back too.

For users with BTC on LBTC, don't attempt any peg-in or peg-out now. Liquid has confirmed that deposits and withdrawals have been paused. But even once the freeze lifts, wait until there's official confirmation that the network has restarted.

Your funds might end up getting stuck on the bridge, making it difficult for both parties to verify a transaction. Liquid has specifically advised users not to send Bitcoin to its peg-in addresses until it confirms that the network has restarted.

You should also reassess how much you hold on sidechains. Sidechains like LBTC and other wrapped Bitcoins serve a specific purpose, such as better speed, lower fees, or smart contracts, and don’t inherit the same security infrastructure as the base chain.

If you don’t need these features, consider how much you're comfortable holding on these sidechains. You can keep the bulk of your holdings in a wallet or storage solution that gives you greater control over your private keys

Incidents like these also increase the risk of related attacks. Some Liquid-integrated exchanges and SideSwap hold your personally identifiable information, including KYC details such as names, email addresses, phone numbers, and others.

While the specific incident is a protocol-level bug, in a follow-up attack, attackers could target the platform itself to steal these personal credentials. This could then increase the risk of financial fraud, phishing messages, and identity theft.

Make sure you use two-factor authentication (2FA) for all the crypto platforms that you transact on. Also, choose strong, unique passwords for all your crypto exchange accounts and other online accounts. A good password manager can help you generate and securely store them.

It also pays to get an identity theft protection service, as it can help prevent the misuse of your data. It scans the dark web and other leaked databases to look for your sensitive information and alert you if it finds anything.

Bottom line

Although crypto sidechains offer several advantages, they don’t inherit the same security structure as the base layer. A single validation flaw or bug could drain a federation's entire funds, as happened with Liquid.

If you’ve been affected by Liquid’s breach, don’t attempt any peg-in or peg-out on Liquid until the issue has been resolved and the network has officially restarted. For general crypto users, avoid keeping more crypto on exchanges or sidechains than you need. Also, use security guardrails like strong, unique passwords and 2FA.

4.8
Editorial Rating
Get Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Liquid Network’s X post

[2] Liquid Network attacker returns 3,400 BTC after bug fix, retains nearly 600 BTC