Blockstream's Liquid Network, a Bitcoin layer-2 sidechain, halted operations after 4,000 BTC was withdrawn from the federation wallet that backs L-BTC. The withdrawn funds, valued near $320 million, represent approximately 95% of the network's reserve, which previously held roughly 4,200 BTC.
The attackers claimed white-hat status and left an on-chain message stating they were disclosing a bug. "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix," the message said.
Liquid Network stated the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but confirmed the key was not compromised. On-chain data showed two Bitcoin transactions emptied most of the reserve, with a 2.5 BTC transfer followed by a payout of nearly 3,996 BTC to a single address. The federation wallet now holds just over 200 BTC.
Other Liquid Network assets including USDT, DePix, and real-world assets remain unaffected by the incident.
Skepticism Over White-Hat Claims
Several industry observers rejected the attackers' characterization as white hats. Ledger CTO Charles Guillemet argued that legitimate security researchers typically disclose flaws before moving collateral, comparing the incident to past bridge hacks where attackers later attempted negotiations.
Former Blockstream CSO Samson Mow noted that a Signal contact request did not originate from the address holding the 4,000 Bitcoin, suggesting the contact communications may not represent the actual attackers.
The incident raises questions about L-BTC's peg integrity. Until a public resolution occurs between Blockstream and the self-claimed white-hat hackers, L-BTC's 1:1 backing depends on trust in the remaining reserve, software fixes, and recovery of the withdrawn coins.


