Liquid Network Hack Drains $320M,
Hackers Return Most of It
Self-declared “white hats” emptied 95% of a Bitcoin sidechain’s reserve, then demanded a bug fix before they’d give most of it back.
The Liquid Network hack didn’t look like a typical crypto heist from the moment it started, and it got stranger from there. On September 6, roughly 4,000 of the 4,200 Bitcoin held in the federation wallet backing Blockstream’s Liquid sidechain vanished in a single transaction that cost about 21 cents in fees. Liquid immediately disabled its bridge nodes, paused all transactions, and told exchanges to freeze L-BTC deposits and withdrawals.
Here’s where it gets unusual: no private key was compromised. The funds moved out through SideSwap, a normal, approved trading platform, after a software bug in Liquid’s underlying Elements codebase let a transaction create more L-BTC than the network actually had backing for. And instead of disappearing, the attackers left an on-chain message identifying themselves as “whitehats” and asked Blockstream to fix the bug before they’d send the money back.
This piece breaks down exactly how the bug worked, what the hackers demanded, how much came back, and why security researchers are still arguing over whether to call this a rescue or a ransom.
What Broke Inside Liquid Network
A range-proof verification bug in Elements let a transaction mint more L-BTC than the network’s Bitcoin reserves could back.
How Liquid Network Funds Left
Through SideSwap, an approved trading platform — not a stolen private key or compromised federation signer.
Fix It, Then We Pay
The attackers refused to return funds until Blockstream confirmed every node was patched against the same bug.
Rescue or Ransom?
Security figures are split on whether keeping $47M as an unsolicited “bounty” counts as ethical disclosure or extortion.
September 6: Liquid Network Loses 4,000 Bitcoin
The DrainLiquid’s federation wallet held about 4,200 BTC backing the network’s L-BTC token, used by exchanges for faster Bitcoin settlement. In a single transaction costing roughly 21 cents in fees, close to 4,000 of that Bitcoin moved out, leaving the reserve at approximately 197 BTC — about 5% of what it started with.
The Bug That Made It Possible
Root CauseLiquid said the SideSwap Peg-out Authorization Key used to move the funds was not itself compromised. Instead, Blockstream traced the issue to a range-proof verification bug in Elements, the open-source software powering Liquid, which allowed certain nodes to accept a transaction that effectively created L-BTC the network didn’t actually have backing for.
“Fix the Bug First, Then We Pay You Back”
The DemandAfter consolidating the funds, the attackers left an on-chain message identifying themselves as “whitehats” and initiated contact with Blockstream through PGP-signed messages. Their condition was blunt: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
White Hats or Extortionists?
The DebateThe group returned about 3,400 of the 4,000 BTC (roughly $262.6 million) but kept around 598 BTC (about $47 million) as a self-appointed bounty. Ledger CTO Charles Guillemet wrote on X that the attackers “don’t seem to be white hats, and they don’t seem to be the usual criminals either.” Others were less ambiguous — Gart founder Alena Vránová called it extortion outright, arguing that exploiting a bug and holding funds hostage for a fix isn’t the same as responsible disclosure.
They returned 85% of the money
and still call it a bounty, not a ransom.
- Don’t attempt deposits or withdrawals until Liquid and its federation members confirm the network has fully resumed normal operation.
- Check official channels only — Blockstream and Liquid’s own accounts, not third-party threads, for the latest reserve and restart status.
- Review any exchange holding L-BTC for its own statement on whether your balance is fully backed again.
- Treat “white hat” claims with skepticism — a group returning funds after a demand doesn’t automatically make the original exploit legal.
⚠️ Why the Liquid Network Story Isn’t Over
1. Returning funds doesn’t erase the exploit. Legal experts note that draining a wallet and demanding conditions before repayment can still meet the legal definition of extortion, regardless of the attacker’s stated intent.
2. The $47M “bounty” was never offered. Blockstream didn’t agree to pay that amount — the attackers simply kept it, which is a meaningfully different situation than a negotiated bug bounty program.
3. The underlying trust model took a hit. A federation built on 15 members required only a single flawed code update to put the entire reserve at risk, raising questions about how “decentralized” the security actually is.