CryptoDeveloping

Hackers Return 3,400 of 4,000 BTC to Liquid Network, Talks Ongoing for Remaining $47M

Self-proclaimed 'whitehats' claim they drained the federation wallet to expose a vulnerability and will return the rest once the bug is fixed

edit
By LineZotpaper
Published
Updated
Read Time3 min
Sources4 outlets
Hackers who drained approximately $320 million in Bitcoin from the Liquid Network federation wallet have returned 3,400 of the 4,000 BTC they took, according to a CoinDesk report on Monday. Talks are underway for the remaining 600 BTC, worth roughly $47 million at current prices, as the hackers — who claim to be 'whitehats' — say they will return the funds after the underlying vulnerability is patched.

The Liquid Network, a Bitcoin sidechain developed by Blockstream, confirmed on Sunday that about 4,000 BTC — roughly 95% of the federation wallet's balance — had been withdrawn by individuals it cautiously described as 'purported white-hat hackers.' The wallet held approximately 4,200 BTC before the incident.

In an on-chain message embedded in a Bitcoin transaction, the hackers identified themselves as 'whitehats' and requested an audience with Liquid, promising to return the money once the vulnerability that enabled the exploit is fixed. 'Please fix the bug first,' the message read. 'The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.'

Liquid responded on-chain with contact details for its security team, and the parties subsequently moved their communications to an encrypted channel. As of Monday, 3,400 BTC had been returned, leaving 600 BTC outstanding.

The mechanics of the exploit are unusual. Liquid stated that the coins were withdrawn through SideSwap, a decentralized exchange built on the sidechain, using the Peg-out Authorization Key (PAK). However, Liquid said that neither SideSwap's key nor any other PAK appeared to have been compromised. SideSwap confirmed that a customer sent 4,000 L-BTC to its peg-out service, which it processed normally, and the Liquid Federation paid out 3,996 BTC to the customer's Bitcoin address 23 minutes later. SideSwap noted that its systems had no way to distinguish those coins from any other L-BTC.

Launched in 2018, Liquid is a federated sidechain designed to move Bitcoin faster and more privately than the main chain. It is secured by a federation of more than 80 exchanges, brokers, and other financial firms, with 15 rotating functionaries requiring 11 signatures to move funds. The Bitcoin network itself was unaffected, and other assets issued on Liquid, including stablecoins, do not appear to have been directly compromised.

Liquid has suspended transactions and warned of service disruptions as federation members work to restore service. Exchanges have been asked to suspend L-BTC deposits and withdrawals.

§

Analysis

Why This Matters

  • This incident highlights the security risks of federated sidechains, where a small group of trusted parties collectively manage the Bitcoin backing L-BTC, unlike Bitcoin's decentralized proof-of-work model.
  • The return of the majority of funds is a positive outcome, but the remaining $47 million in limbo underscores the fragility of trust in Layer 2 solutions used by exchanges.
  • The hackers' claim to be whitehats sets a contentious precedent: self-appointed security researchers draining wallets to force fixes, which could encourage copycat exploits in other networks.

Background

Liquid is a Bitcoin sidechain developed by Blockstream that allows faster and more private transactions than the main Bitcoin blockchain. It is secured by a federation of over 80 financial firms, with 15 functionaries responsible for signing blocks and managing the multisig wallet that holds the pegged-in Bitcoin. The network is used by exchanges and other institutions for settlement. This is not the first high-profile crypto exploit in recent months: the trading platform Drift suspended deposits and withdrawals after a suspected $270 million hack in April, and over $1.7 billion in Bitcoin was reported stolen in 2025 alone.

Key Perspectives

Blockstream / Liquid Network: They are working with the hackers via encrypted channels and have suspended operations. They have not confirmed the nature of the vulnerability but maintain that no keys were compromised. The return of 3,400 BTC suggests some level of cooperation. Hackers (self-proclaimed whitehats): They claim to have drained the wallet to expose a security flaw and say they will return the remaining Bitcoin once the vulnerability is patched and all nodes are updated. Their on-chain message framed the action as a safety measure. Critics / Skeptics: While some may view the hackers as vigilantes, others caution that such unauthorized extractions — even with promises to return funds — can destabilize markets and erode trust in federated networks. The fact that $47 million is still outstanding leaves uncertainty about the hackers' true intentions.

What to Watch

  • Whether the remaining 600 BTC are returned within days, which would strengthen the whitehat narrative, or whether negotiations break down, leading to a protracted dispute or loss of funds.
  • Details of the vulnerability itself: once disclosed, it will reveal whether the exploit was a bug unique to Liquid or a systemic issue in federated sidechain designs.
  • Regulatory response: if the funds are not fully returned, authorities may treat the incident as a theft, potentially leading to criminal investigations.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.