In an unusual twist on crypto theft, attackers drained approximately $320 million worth of Bitcoin from Liquid Network's federation wallet but claimed they are white-hat hackers who will return the funds once the vulnerability is fixed. The exploit, which emptied roughly 95% of the wallet's balance, has sent ripples through the cryptocurrency infrastructure sector.

What You Need to Know

Liquid Network is a Bitcoin sidechain designed for faster and more private transactions, secured by a federation of over 80 firms. The stolen coins left through the Peg-out Authorization Key belonging to SideSwap, though neither that key nor any others were compromised. The hackers communicated via on-chain messages, requesting a bug fix before returning the funds. This incident adds to a year of heavy crypto infrastructure losses, with $17 billion in Bitcoin stolen in 2025 alone.

The Unusual Exploit

On September 6, Liquid confirmed that 4,000 BTC, roughly 95% of the federation wallet's balance, had been withdrawn. The attackers embedded a message in a Bitcoin transaction identifying themselves as white-hats. "Please fix the bug first," the on-chain message said. "The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." Liquid responded on-chain with its security team's contact and moved communications to an encrypted channel. The platform suspended transactions, warning of service disruptions as federation members worked to restore service.

How the Attack Worked

Liquid Network is a federated sidechain that settles blocks roughly every minute. Instead of relying on miners, a group of 15 rotating functionaries, requiring 11 signatures, handles block signing and multisig wallet operations. According to Liquid, the coins exited through the Peg-out Authorization Key belonging to SideSwap, a decentralized exchange built on the sidechain. Neither that key nor any others were compromised. SideSwap confirmed that a customer sent 4,000 L-BTC to its peg-out service, which processed the order as usual, and the Liquid Federation paid out 3,996 BTC to the customer's Bitcoin address 23 minutes later. SideSwap stated its systems could not distinguish those coins from any other L-BTC.

  • Typical crypto heists: Attackers steal keys through phishing or device compromise, gaining direct access to wallets.
  • Liquid exploit: The coins moved through a legitimate peg-out process; the key was not stolen but exploited due to a vulnerability.
  • Hackers’ behavior: Rather than vanishing, they left on-chain messages identifying as white-hats and promised return after patching.

Why This Matters

The exploit highlights a critical vulnerability in federated sidechain models, where trust is placed in a rotating group of functionaries and multisig controls. The Peg-out Authorization Key served as a single point of attack even though it was not compromised. This incident could erode confidence in sidechain security, pressuring platforms like Liquid and its federation members to conduct deeper security audits and implement more robust vulnerability reporting mechanisms. For the broader crypto ecosystem, the attack adds to a punishing year of infrastructure losses, including $17 billion in Bitcoin stolen in 2025 alone. The white-hat claim, if fulfilled, may restore some trust, but the episode underscores that even well-federated networks remain exposed to novel exploit vectors.