Home / News / Bitcoin / White-Hat Hackers Drain $320 Million BTC Via SideSwap Key on Liquid Network

Written By

White-Hat Hackers Drain $320 Million BTC Via SideSwap Key on Liquid Network

White-Hat Hackers Drain $320 Million BTC Via SideSwap Key on Liquid Network
White-Hat Hackers Drain $320 Million BTC Via SideSwap Key on Liquid Network

What to Know

  • 4,000 BTC (about $320 million) left the Liquid Federation wallet on September 6, and Blockstream is calling it a possible white-hat hack.
  • The withdrawal used the SideSwap peg-out authorization key, but Liquid says the key itself was never compromised.
  • Exchanges have suspended LBTC deposits and withdrawals while Liquid’s bridge nodes stay offline.
  • Ledger CTO Charles Guillemet compared the incident to the Ronin hack and doubts the white-hat claim.

Liquid Network, the Bitcoin sidechain built by Blockstream, ground to a halt this week after someone pulled roughly 4,000 BTC, worth about $320 million, out of its Federation wallet. The party responsible says they are white-hat hackers. They claim they will send the coins back once a security bug gets fixed. Blockstream has confirmed the withdrawal and paused new transactions on the sidechain while it investigates. Not everyone is convinced the hackers are telling the truth.

Liquid Network Halts After $320 Million BTC Drain

Liquid confirmed the incident in an update posted on Saturday, September 6. The company said the coins moved out using the SideSwap PAK, short for Peg-out Authorization Key, though it stressed the key itself was never compromised. No other keys on the network were put at risk, according to the statement. Crypto exchanges got word of the breach fast. Several platforms have already suspended LBTC deposits and withdrawals, and more are expected to pause trading while the situation gets sorted out. Anyone wanting the fuller timeline can check the Liquid Network $320 million BTC withdrawal report published as the story broke.

Other assets on Liquid were spared. Liquid said USDT, DePix and tokenized real-world assets on the network were not touched by the withdrawal. Bridge nodes have also been switched off for now, which means no new transactions can move across the sidechain. In practice, that leaves Liquid frozen until the Federation members finish their review.

LBTC is the tokenized version of Bitcoin that trades on Liquid, redeemable for real BTC through the Federation’s multisig setup. Suspending deposits and withdrawals is the standard playbook when a bridge like this gets hit, since it stops stolen or disputed funds from being laundered through exchange order books while the network sorts out what happened. It is blunt, but it works.

Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.

— Liquid Network, official update

What Is the SideSwap Peg-Out Authorization Key?

A peg-out authorization key, or PAK, is a permission system Liquid uses to control which Bitcoin addresses can receive coins when BTC moves off the sidechain. SideSwap runs one of these keys. Whoever drained the wallet used that SideSwap PAK to authorize the transfer, per the SideSwap peg-out authorization key mechanism, without cracking the key’s private material.

That distinction matters a lot for Liquid users. A stolen private key would mean every wallet on the network is exposed and funds could be moved without permission at will. A misused authorization key is narrower. It let one specific actor push a peg-out through the system, but it did not hand them control over the Federation’s core signing infrastructure. That is likely why Liquid was able to say, fairly confidently, that the rest of the network stayed safe.

Blockstream and the Hacker Argue It Out On-Chain

The back-and-forth between Blockstream and the person claiming responsibility played out almost entirely in public. According to Bitcoin advocate Samson Mow, the hacker preferred posting messages inside Bitcoin transaction data over emailing anyone directly. The exchange started at 11:30 AM PDT on Saturday, when the hacker wrote a short note claiming to be a white hat and asking Blockstream to make contact on-chain. Blockstream answered about an hour later, at 12:31 PM, and asked the sender to reach the company’s security team by email instead. When that request went nowhere, Blockstream sent an encrypted, PGP-signed message directly to the hacker’s public key.

By 7:20 PM, the hacker said they planned to send most of the funds back and asked whether a particular address would work. About an hour after that, they added the message above about patching the chain first. Blockstream replied simply, “Yes, thank you,” at 8:30 PM. As of 9:12 PM PDT, roughly 3,998.5 BTC had still not moved. Neither side has posted anything new since.

The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.

— Anonymous hacker, on-chain OP_RETURN message

Ledger’s CTO Doubts the White-Hat Story

Not everyone is buying the white-hat framing. Ledger chief technology officer Charles Guillemet said he was skeptical, pointing out that legitimate security researchers do not typically drain a bridge first and negotiate afterward. He compared the episode to the 2022 Ronin hack, where attackers stole around $625 million after compromising validator keys, and to the Euler Finance exploit, where the attacker also tried to negotiate a return once caught. For the full breakdown of his reasoning, see the Charles Guillemet Ledger CTO Ronin comparison coverage. Guillemet said the hacker’s move to Signal did little to change his mind either.

Here is the part that deserves more scrutiny. Guillemet also admitted that criminal groups do not usually reach out to their victims either, which cuts both ways. That is the real tension in this story. A true white hat would not need to hold $320 million hostage while asking a company to patch its own bridge. But a thief hoping to launder stolen Bitcoin would not typically hand back 3,998.5 BTC and wait around for confirmation either. Until the funds actually move, calling this a rescue or a robbery is mostly a guess.

What This Means for Liquid Network and LBTC Holders

For now, LBTC holders are stuck waiting. Liquid is effectively frozen, exchanges have paused withdrawals, and the sidechain cannot process new transactions until the Federation finishes patching whatever flaw the hacker referenced. Traders who rely on Liquid for fast, private Bitcoin settlement between exchanges are the ones feeling this the most, since the network’s whole pitch is speed and confidentiality that regular Bitcoin transactions do not offer.

If the money comes back and the bug gets fixed quietly, this becomes a footnote in Bitcoin Layer 2 history. If it does not, Liquid joins a growing list of bridges that learned about their own weaknesses the hard way. Either way, Blockstream now has to prove that a sidechain can survive a $320 million stress test without losing user trust. So far, the hacker is still holding almost all of it.

Frequently Asked Questions

What happened to Liquid Network?

Someone withdrew about 4,000 BTC, worth roughly $320 million, from the Liquid Federation wallet using the SideSwap peg-out authorization key. Blockstream paused the sidechain’s bridge nodes and confirmed the withdrawal, while the party responsible claims to be a white-hat hacker planning to return the funds after a bug gets fixed.

Was the SideSwap key hacked?

No. Liquid said the SideSwap peg-out authorization key itself was not compromised and that no other keys on the network were put at risk. The key was simply used to authorize a transfer, which differs from a full custody breach where an attacker gains permanent control.

Is my LBTC safe right now?

Liquid paused bridge nodes, so no new transactions can move across the sidechain, and several exchanges have suspended LBTC deposits and withdrawals as a precaution. Other assets on Liquid, including USDT, DePix and real-world assets, were reportedly not affected by the withdrawal.

Are the Liquid Network hackers really white hats?

It is unclear. The hacker claims to be a white hat planning to return the funds once a bug is fixed. Ledger CTO Charles Guillemet is skeptical, noting real white hats rarely drain a bridge first, though he admits typical thieves don’t usually negotiate with victims either.

This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.

Share With Your Network :

Facebook
X
LinkedIn
Pinterest
Reddit
Telegram
WhatsApp
Email
Threads

James Wright

James Wright is a Crypto News Reporter at TheCryptoWorld, covering breaking developments across exchanges, regulation, and institutional adoption. With a journalism background rooted in business reporting, James transitioned to full-time crypto coverage in 2020 after covering the rise of decentralized finance for an independent fintech publication. He focuses on delivering fast, accurate reporting on the stories that move markets — from SEC enforcement actions to major exchange listings and corporate treasury moves.
0 0 votes
Article Rating
Subscribe
Notify of
guest

3 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Tomas Lindqvist
Tomas Lindqvist
3 days ago

so a federated sidechain with an 11-of-15 functionary set still had one signer key compromised through SideSwap, and we’re calling this white-hat because they gave it back? the peg-out surface has been the weak point since 2018 and nothing about that has actually changed

Anya Petrova
Anya Petrova
3 days ago

white-hat my ass, if you drain $320M without permission you’re a thief regardless of what you do after

Rin Watanabe
Rin Watanabe
3 days ago

reminds me of the Poly Network incident in 2021, same script, drain funds then negotiate a bounty and rebrand as ethical research

Table of Contents

Check also

Specific Crypto details

Fear & greed index
49
▲ +4 from yesterday
Updated: April 11, 2026
▼ Fear
Recovering from extreme fear
0
Extreme fear
25
Fear
50
Neutral
75
Greed
100
Extreme greed
Yesterday
45
Fear
Last week
30
Fear
April 8
11
Extreme fear
0 0 votes
Article Rating
Subscribe
Notify of
guest

3 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Tomas Lindqvist
Tomas Lindqvist
3 days ago

so a federated sidechain with an 11-of-15 functionary set still had one signer key compromised through SideSwap, and we’re calling this white-hat because they gave it back? the peg-out surface has been the weak point since 2018 and nothing about that has actually changed

Anya Petrova
Anya Petrova
3 days ago

white-hat my ass, if you drain $320M without permission you’re a thief regardless of what you do after

Rin Watanabe
Rin Watanabe
3 days ago

reminds me of the Poly Network incident in 2021, same script, drain funds then negotiate a bounty and rebrand as ethical research

Solana ETF Inflows Overtake XRP as SOL Nears $100

Altcoin Predictions

2 weeks ago

Solana ETF Inflows Overtake XRP as SOL Nears $100

Sarah Chen

Satoshi Nakamoto's Bitcoin Holdings Surge as BTC Nears $81K

Bitcoin

2 weeks ago

Satoshi Nakamoto’s Bitcoin Holdings Surge as BTC Nears $81K

James Wright

Ripple's Evernorth Gets SEC Approval for Nasdaq XRP Listing

Altcoins

2 weeks ago

Ripple’s Evernorth Gets SEC Approval for Nasdaq XRP Listing

James Wright

Bitwise Solana ETF Tops $1 Billion as SOL Price Rally Continues Higher

Altcoins

2 weeks ago

Bitwise Solana ETF Tops $1 Billion as SOL Price Rally Continues Higher

James Wright

Market Analysis

The Future of Crypto, Covered Daily

Real-time news, expert analysis, and market insights  trusted by thousands of crypto investors worldwide.

You have been successfully Subscribed! Ops! Something went wrong, please try again.
3
0
Would love your thoughts, please comment.x
()
x