Liquid Network Sees $320M BTC Drain, Hackers Demand Full Patch Before Return

Self-described white hats hold about $320 million in Bitcoin after a Liquid Network security incident. (Image: Shutterstock)
Self-described white hats hold about $320 million in Bitcoin after a Liquid Network security incident. (Image: Shutterstock)

Liquid Network said self-described white-hat hackers withdrew about 4,000 Bitcoin (BTC) worth $320 million from its federation wallet and promised repayment only after a network bug is fixed.

Key Points:

  • Liquid Network said roughly 4,000 BTC left its federation wallet in a security incident.
  • The hackers said they would return most funds only after every affected node receives a patch.
  • About 3,998.5 BTC remained unmoved at 9:12 p.m. PDT, while the network stayed effectively paused.

Liquid Bitcoin Drain

Liquid Network said the roughly 4,000 BTC withdrawal used the SideSwap Peg-out Authorization Key, or PAK, while adding that the key itself was not compromised. No other federation keys were at risk. Liquid said other assets on the network were not affected.

The network also disabled its bridge nodes, preventing new transactions from being submitted and effectively pausing the sidechain while federation members worked on a fix.

Blockstream attempted to contact the parties through a signed on-chain message after the hackers asked to communicate publicly through Bitcoin transaction data rather than email.

Samson Mow said the exchange began at 11:30 a.m. PDT on Sept. 6, and the hackers later supplied a Signal contact while Blockstream sent an encrypted, PGP-signed message.

At 7:20 p.m., the hackers said they planned to return most of the funds and asked whether a specified address was acceptable. About an hour later, they wrote, “Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” Blockstream replied, “Yes, thank you,” at 8:30 p.m., while about 3,998.5 BTC remained unmoved as of 9:12 p.m. PDT.

Also Read: iPhone Ultra May Drop Face ID And 4 More Features Despite $2,000+ Price

Ledger CTO Doubts

Ledger Chief Technology Officer Charles Guillemet questioned the white-hat description, saying legitimate security researchers would not normally drain a bridge and then ask the affected project to make contact on-chain. The later move to Signal did not change his assessment.

Guillemet noted an unusual counterpoint: criminal groups do not typically open a direct conversation with their victims either, while nearly all the withdrawn Bitcoin remained under the hackers’ control and repayment stayed tied to a complete patch.

Past bridge exploits provide reasons for caution when attackers later describe themselves as cooperative. The Ronin hack involved about $625 million stolen after validator keys were compromised, while the Euler exploiter later negotiated with the project and returned all recoverable funds.

Read Next: Bitcoin Trails Gold By 10X, And CZ Thinks That Ends Next Cycle

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer