Liquid Network Hack: $320 Million in Bitcoin Drained in Major Security Incident
Liquid Network has suffered a major security incident after approximately 4,000 BTC worth about $320 million was withdrawn from its Federation wallet on September 6. The withdrawal represented roughly 95% of the Bitcoin reserves backing the network, which stood at about 4,200 BTC before the incident. Liquid subsequently paused network activity while its federation members investigated how the transaction passed through the peg-out system.
The incident is unusual because Liquid says the SideSwap Peg-out Authorization Key, or PAK, used in the transaction was not compromised. The network has also said its other authorization keys were unaffected. That leaves a critical question at the center of the investigation: how did almost the entire Bitcoin reserve leave through a mechanism that apparently used valid authorization?
The transaction involved approximately 3,996 BTC being released from the federation reserve after around 4,000 LBTC was sent through SideSwap’s peg-out service. The corresponding LBTC was burned on Liquid. Under normal circumstances, that process converts LBTC back into Bitcoin on the main chain, making the mechanics of this particular transaction especially important to understanding the incident.
How the Liquid Network Incident Happened
Liquid is a Bitcoin sidechain designed to provide faster and confidential transactions while supporting assets including stablecoins and tokenized securities. Its two-way peg allows Bitcoin to move into Liquid as LBTC and later return to the Bitcoin network through a controlled peg-out process. Federation members manage the Bitcoin reserves that support this system.
According to subsequent reporting, the withdrawn LBTC appears to have been created through an Elements software vulnerability rather than through a direct compromise of the federation’s signing keys. That distinction is crucial because it suggests the security failure may have occurred at the asset-creation or validation layer, allowing invalid LBTC to enter a legitimate redemption process. The exact technical vulnerability has not yet been publicly disclosed in full.
Related: Bitcoin Computer Unlocks Trustless Programmable Escrows on Bitcoin and Litecoin
SideSwap has also said its authorization key and systems were not compromised. The service reportedly processed the transaction normally because the invalid LBTC could not be distinguished from legitimate LBTC during the peg-out process. That means the problem may have exploited assumptions built into the broader Liquid architecture rather than simply stealing a private key.
The actors controlling the withdrawn Bitcoin have claimed to be white-hat hackers. An on-chain message reportedly stated, “we are whitehats. contact us on chain.” But that claim has not been independently verified, and the funds had not been confirmed returned as of September 7.
That uncertainty matters because legitimate security researchers normally disclose vulnerabilities through coordinated channels rather than first moving hundreds of millions of dollars. Ledger CTO Charles Guillemet has publicly questioned whether the behavior fits the conventional definition of a white-hat intervention. Until the funds are returned and the technical details are established, describing the actors as rescuers remains premature.
Why the $320 Million Loss Matters for Bitcoin
Liquid responded by disabling bridge nodes and halting new transactions, while exchanges were notified to pause or prepare to pause LBTC deposits and withdrawals. Other Liquid assets, including USDT, DePix and tokenized real-world assets, were reported as unaffected by the incident. The immediate damage therefore centers on the Bitcoin reserve and the mechanism connecting BTC with LBTC.
The episode is also a reminder that Bitcoin itself was not hacked. Bitcoin’s base network continued operating normally, while the vulnerability involved infrastructure built around a Bitcoin sidechain. This distinction is essential when assessing the incident because the security assumptions of a federated bridge are different from those of Bitcoin’s decentralized proof-of-work network.
Liquid’s model depends on a federation of functionaries managing the two-way peg and the Bitcoin held in its multisignature wallet. The network’s technical design is intended to provide faster settlement and confidential transactions, but the incident shows that additional layers introduce additional assumptions that must hold for the system to remain secure.
Related: Could Pension Fund Money Push Bitcoin to New Highs? The Math Explained
For users, the immediate priority is the restoration of normal network operations and a clear explanation of the vulnerability. For developers, the bigger issue is whether the flaw can be reproduced, whether similar attacks could affect other Elements-based deployments and what safeguards can prevent invalid assets from reaching a valid peg-out pathway.
The incident also creates a difficult test for Liquid’s reputation among exchanges, institutions and other users that rely on the network for Bitcoin settlement. A system designed to provide additional functionality around Bitcoin must ultimately convince users that its bridge and custody assumptions are robust enough to justify those additional layers of complexity.
At roughly $320 million, the headline loss is enormous, but the technical lesson may prove more important than the dollar value. Nearly 95% of Liquid’s Bitcoin reserves left through a transaction that the network says did not involve compromised authorization keys. Until investigators fully explain how that happened, the incident will remain a serious warning about the security assumptions surrounding federated Bitcoin sidechains and their peg mechanisms.















