Bitcoin's Liquid Network, a layer-2 privacy sidechain, suffered a 4,000 BTC exploit over the weekend, representing roughly 95% of its total reserves. The hackers, who identified themselves as white-hats, subsequently returned 3,400 BTC—approximately 85% of the drained amount—to the Federation's multisig wallet.
The exploit involved a software vulnerability that allowed attackers to print unbacked L-BTC tokens and redeem them for actual Bitcoin. The hackers explicitly flagged this vulnerability and demanded that Blockstream, the network's developer, deploy a patch before releasing the stolen funds. Once the security fix was implemented, the funds were returned.
The group continues to hold approximately 598.5 BTC with no public communication from either the hackers or Blockstream regarding the remaining coins.
Network Response and Current Status
Blockstream and federation members disabled bridge nodes following the breach, effectively freezing the peg-out system. Major exchanges including Bitfinex and the Aqua wallet suspended all L-BTC deposits and withdrawals as a containment measure.
Tokenized assets on the Liquid network, such as Liquid-based Tether and real-world assets, remained unaffected by the incident.
Depegging Risk
The primary concern centers on L-BTC's backing mechanism. The network relies on a 1:1 Bitcoin backing to maintain L-BTC's value. The 600 BTC deficit could force L-BTC to trade at a discount to Bitcoin if the shortfall remains uncovered, potentially triggering capital flight and further diminishing L-BTC's value.
Blockstream co-founder and CEO Adam Back has not yet commented on the matter. The Liquid Network's latest communication indicates that federation members are working to resolve the issue.


