Liquid Network has paused new transaction activity after roughly 4,000 bitcoin, worth about $320 million at the time, was withdrawn from the federation wallet that supports its Bitcoin-pegged asset.

The Bitcoin sidechain said in an official update on September 6 that actors it described as purported white-hat hackers had removed around 4,000 of the approximately 4,200 BTC held in the wallet. Liquid said it disabled bridge nodes, notified exchanges to suspend L-BTC deposits and withdrawals, and was working with federation members to restore normal activity.

The actors have claimed they intend to return most of the funds after a vulnerability is patched, according to subsequent on-chain messages reported by Galaxy Research head Alex Thorn. That promise had not resulted in a publicly confirmed return as of September 7, and neither Liquid nor Blockstream had published a technical root-cause analysis.

The withdrawal used an authorized peg-out route

Liquid said the funds were withdrawn through the Peg-out Authorization Key, or PAK, associated with SideSwap, a federation member that provides settlement and peg-out services. It said the SideSwap key itself was not compromised, and that it had found no compromise of other keys.

That distinction leaves the mechanism of the incident unresolved. A valid PAK is intended to restrict withdrawals to authorized destinations, while the federation’s functionaries separately sign transactions that release BTC on the Bitcoin main chain. Liquid has not said how a withdrawal of this size passed those controls without the relevant key being stolen.

Reuters reported that Liquid halted new transactions and warned that Liquid wallets would be affected. The network said other assets issued on Liquid, including USDT and DePix, were not directly affected.

Public on-chain analysis cited by The Defiant identified two Bitcoin transactions totaling about 3,998.5 BTC. The recipient later placed an on-chain message claiming to be a white-hat actor and inviting contact. Blockstream responded through a separate on-chain message directing the actor to its security contact.

Later messages analyzed by Thorn indicated that the actor proposed returning most of the BTC only after Blockstream patches the vulnerability and federation nodes install the fix. Those messages offer a possible recovery path, but they do not establish the actors’ identity or intent, and a partial-return proposal would still leave the amount retained unresolved.

Incident tests Liquid’s federation model

Liquid is a Bitcoin sidechain developed by Blockstream for faster settlement and digital-asset issuance. Under its two-way peg, users lock BTC and receive an equivalent amount of L-BTC on Liquid. To exit, users burn L-BTC and an authorized provider initiates a peg-out that releases BTC from the federation-controlled wallet.

The broader Liquid Federation includes more than 80 exchanges, infrastructure companies and asset managers, while a subset operates the specialized servers that sign blocks and manage the peg, according to Blockstream’s documentation. The model gives users faster and confidential transactions but places the peg under a defined set of operators and authorization controls rather than Bitcoin’s base-layer consensus.

The incident did not compromise the Bitcoin network itself. It affected the separate infrastructure used to issue and redeem L-BTC, making the immediate questions whether the actors return the funds, when the network can safely resume, and what flaw allowed the peg-out.

Blockstream had already been researching a bridge design with lower trust assumptions. A May roadmap described a longer-term BitVM-style bridge as an active research track rather than a production system. The September withdrawal occurred under Liquid’s existing federated architecture.

Until Liquid publishes a post-incident report and confirms recovery, the $320 million figure should be treated as the approximate value moved, not a final loss. The actors’ white-hat description also remains a claim, not a verified characterization.

AI is turning old crypto code into a new attack surface, says CoinEx chief analyst Jeff Ko [Q&A]