Attackers who drained roughly $320 million in bitcoin from the Liquid Network have returned 3,400 of the 4,000 coins they took, leaving about 598 BTC, worth roughly $47 million, still outstanding. The Bitcoin sidechain remains paused while Blockstream works to patch the underlying flaw and restore full backing for its L-BTC token.
The breach happened on September 6, when nearly 4,000 BTC was pegged out of the federation wallet that secures Liquid’s bitcoin-backed token. The wallet held about 4,200 BTC before the incident, so the withdrawal removed roughly 95 percent of everything pegged to the sidechain, according to estimates from Galaxy Research. It was one of the largest single-day losses ever recorded against a Bitcoin-adjacent bridge, and it happened without any key being stolen.
How the withdrawal worked
The funds left through the peg-out authorization key belonging to SideSwap, a federation member that operates a withdrawal service. Liquid said neither the SideSwap key nor any other PAK was compromised. The problem sat deeper, in the Elements software that underpins the sidechain: a bug allowed the attackers to mint unbacked L-BTC tokens and exchange them for real bitcoin through the normal peg-out process.
SideSwap later explained that a customer sent 4,000 LBTC to its peg-out service at 14:05 UTC, and the federation paid out 3,996 BTC twenty-three minutes later. The coins were consolidated into a single bitcoin address carrying an on-chain message that read “we are whitehats. contact us on chain.” Blockstream replied with a signed message of its own, and the two sides moved to encrypted channels.
The people behind the withdrawal said they would return most of the bitcoin once the vulnerability was fixed and every node patched. “Please fix the bug first,” their message said. “The chain is under risk at latest commit right now.” They made good on that promise on September 8, sending 3,400 BTC back, which left about 15 percent of the haul unreturned.
Network still frozen
Liquid disabled its bridge nodes immediately after the incident and asked exchanges to suspend L-BTC deposits and withdrawals. The sidechain has not restarted. In an incident report on X, Liquid said discussions between Blockstream and the individuals responsible are ongoing to secure the return of the remaining funds, though it gave no timeline and no details on the terms.
Assets issued on Liquid other than L-BTC, including USDT, DePix and tokenized real-world assets, were not affected. The attack touched only the peg mechanism between bitcoin and the sidechain. That separation limits the blast radius, but it does little for anyone holding L-BTC, which cannot move until the bridge reopens.
Liquid is a sidechain built by Blockstream for faster, more confidential bitcoin transfers and asset issuance. Every L-BTC in circulation is supposed to be matched one-for-one with bitcoin locked in a shared wallet controlled by federation members, a group that includes exchanges, miners and financial institutions. The September 6 withdrawal broke that assumption almost entirely: within hours, the reserve stash fell to 197 BTC while outstanding L-BTC far exceeded it.
Skepticism about the white hat label
Not everyone accepts the attackers’ self-description. Charles Guillemet, chief technology officer at Ledger, questioned the framing and compared the episode to the Ronin bridge hack, in which attackers took about $625 million after compromising validator keys. He stopped short of calling it outright theft, but his point was that a label someone writes into an on-chain message is not evidence of intent. Until the last coins come back, the white hat designation stays a claim rather than a fact.
Precedent cuts both ways. White hat operations in crypto have sometimes ended with everything returned, sometimes with the attacker keeping a 10 percent cut as a condition, and sometimes with nothing coming back at all. Blockstream has not said whether any payment or bounty is part of the current discussions, and the company has declined to describe the root vulnerability in public, saying only that it sits in the Elements codebase.
What it means for federated bridges
The episode is a stress test for federated bridge design. The federation keys held, but the software layer above them did not, and that distinction now shapes the security work ahead. Blockstream and federation members say they are strengthening security, resolving a chain split and confirming L-BTC is fully backed before the network comes back online.
It also lands at a delicate moment for bitcoin infrastructure. US spot bitcoin ETFs posted their strongest inflow weeks of the year in early September, and institutional money keeps arriving through regulated products. Most of that capital never touches a sidechain, but the incident is a reminder that the layer-2 ecosystem around bitcoin carries risks that the base chain does not. A bridge is software plus a set of humans with keys, and both parts can fail.
Other sidechains and bridges built on similar federation models will face their own questions from users and auditors in the coming weeks. The lesson from Liquid is narrow but uncomfortable: a correctly functioning key ceremony means little if the minting logic above it can be tricked into issuing claims that were never backed in the first place.
For users, the practical advice is unchanged: nothing to do until Liquid announces a restart, at which point wallets and exchanges will resume L-BTC transfers. Anyone who pegged bitcoin into Liquid should watch for an official announcement from the federation rather than third-party claims. The remaining 598 BTC is the number to watch, because it tells you whether the negotiations are real or theater.
