Hackers drain $320M in Bitcoin emptying 95% of Liquid Network wallets


Featured image Hackers drain 320M in Bitcoin emptying 95 of Liquid Network wallets

In a spectacular digital heist that has sent shockwaves through the blockchain world, alleged hackers claiming to be white-hats reportedly managed to drain approximately $320 million worth of Bitcoin from the Liquid Network‘s federation wallet. The incident highlights the growing fragility of even the most sophisticated decentralized financial infrastructure and the complex security challenges facing the crypto landscape.

The breach centered on the Liquid Network, a specialized Bitcoin sidechain developed by Blockstream, designed to facilitate faster and more private transactions. Liquid operates through a unique federated model, secured by a consortium of over 80 exchanges, brokers, and financial firms. Funds within the network are managed by a complex system involving multisig wallets and 15 rotating functionaries who must collectively sign off on large movements.

The scale of the exploit was particularly bewildering. The attackers, who self-identified as purported white-hat hackers, reportedly requested an audience with Liquid via an on-chain message, demanding that the platform fix a vulnerability before returning the stolen funds. Their demand was clear: “Please fix the bug first… Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

The mechanics of the exploit were highly unconventional. Rather than a simple theft, the incident involved sophisticated manipulation of specific protocols. The transaction involved the Peg-out Authorization Key (PAK), linked to SideSwap, a decentralized exchange built on the sidechain. While the hackers claimed they were merely performing a transaction, the system showed that the funds flowed through the established mechanisms, suggesting an intricate exploitation of the sidechain’s protocols rather than a simple key compromise.

Despite the unusual nature of the attack, Liquid’s security team remained firm. They stated that the critical keys had not been compromised. Furthermore, the related service, SideSwap, confirmed that a customer had processed the transfer of L-BTC through their system without any ability to distinguish the tokens from others. This suggests the vulnerability was a flaw in the operational layer rather than a failure of the core security architecture.

In response to the disruption, Liquid suspended transactions and warned of service interruptions while its federation members worked to restore full service. This event comes as the crypto infrastructure faces relentless pressure. Recent months have seen other platforms grappling with massive security failures, including a suspected $270 million hack on a major trading platform and estimates of 17 billion worth of Bitcoin stolen in 2025 alone, driven by evolving impersonation tactics and the increasing use of artificial intelligence in scams.

This incident serves as a stark reminder that while the technology underpinning decentralized finance is revolutionary, the security of the interconnected systems remains a constant, high-stakes battle. For platforms like Liquid, maintaining trust requires not just robust encryption, but a continuous, vigilant focus on the operational integrity of every layer of the network.

You may also like: