What to Know
- 4,000 BTC (about $320 million) left the Liquid Federation wallet on September 6, and Blockstream is calling it a possible white-hat hack.
- The withdrawal used the SideSwap peg-out authorization key, but Liquid says the key itself was never compromised.
- Exchanges have suspended LBTC deposits and withdrawals while Liquid’s bridge nodes stay offline.
- Ledger CTO Charles Guillemet compared the incident to the Ronin hack and doubts the white-hat claim.
Liquid Network, the Bitcoin sidechain built by Blockstream, ground to a halt this week after someone pulled roughly 4,000 BTC, worth about $320 million, out of its Federation wallet. The party responsible says they are white-hat hackers. They claim they will send the coins back once a security bug gets fixed. Blockstream has confirmed the withdrawal and paused new transactions on the sidechain while it investigates. Not everyone is convinced the hackers are telling the truth.
Liquid Network Halts After $320 Million BTC Drain
Liquid confirmed the incident in an update posted on Saturday, September 6. The company said the coins moved out using the SideSwap PAK, short for Peg-out Authorization Key, though it stressed the key itself was never compromised. No other keys on the network were put at risk, according to the statement. Crypto exchanges got word of the breach fast. Several platforms have already suspended LBTC deposits and withdrawals, and more are expected to pause trading while the situation gets sorted out. Anyone wanting the fuller timeline can check the Liquid Network $320 million BTC withdrawal report published as the story broke.
Other assets on Liquid were spared. Liquid said USDT, DePix and tokenized real-world assets on the network were not touched by the withdrawal. Bridge nodes have also been switched off for now, which means no new transactions can move across the sidechain. In practice, that leaves Liquid frozen until the Federation members finish their review.
LBTC is the tokenized version of Bitcoin that trades on Liquid, redeemable for real BTC through the Federation’s multisig setup. Suspending deposits and withdrawals is the standard playbook when a bridge like this gets hit, since it stops stolen or disputed funds from being laundered through exchange order books while the network sorts out what happened. It is blunt, but it works.
Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.
What Is the SideSwap Peg-Out Authorization Key?
A peg-out authorization key, or PAK, is a permission system Liquid uses to control which Bitcoin addresses can receive coins when BTC moves off the sidechain. SideSwap runs one of these keys. Whoever drained the wallet used that SideSwap PAK to authorize the transfer, per the SideSwap peg-out authorization key mechanism, without cracking the key’s private material.
That distinction matters a lot for Liquid users. A stolen private key would mean every wallet on the network is exposed and funds could be moved without permission at will. A misused authorization key is narrower. It let one specific actor push a peg-out through the system, but it did not hand them control over the Federation’s core signing infrastructure. That is likely why Liquid was able to say, fairly confidently, that the rest of the network stayed safe.
Blockstream and the Hacker Argue It Out On-Chain
The back-and-forth between Blockstream and the person claiming responsibility played out almost entirely in public. According to Bitcoin advocate Samson Mow, the hacker preferred posting messages inside Bitcoin transaction data over emailing anyone directly. The exchange started at 11:30 AM PDT on Saturday, when the hacker wrote a short note claiming to be a white hat and asking Blockstream to make contact on-chain. Blockstream answered about an hour later, at 12:31 PM, and asked the sender to reach the company’s security team by email instead. When that request went nowhere, Blockstream sent an encrypted, PGP-signed message directly to the hacker’s public key.
By 7:20 PM, the hacker said they planned to send most of the funds back and asked whether a particular address would work. About an hour after that, they added the message above about patching the chain first. Blockstream replied simply, “Yes, thank you,” at 8:30 PM. As of 9:12 PM PDT, roughly 3,998.5 BTC had still not moved. Neither side has posted anything new since.
The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.
Ledger’s CTO Doubts the White-Hat Story
Not everyone is buying the white-hat framing. Ledger chief technology officer Charles Guillemet said he was skeptical, pointing out that legitimate security researchers do not typically drain a bridge first and negotiate afterward. He compared the episode to the 2022 Ronin hack, where attackers stole around $625 million after compromising validator keys, and to the Euler Finance exploit, where the attacker also tried to negotiate a return once caught. For the full breakdown of his reasoning, see the Charles Guillemet Ledger CTO Ronin comparison coverage. Guillemet said the hacker’s move to Signal did little to change his mind either.
Here is the part that deserves more scrutiny. Guillemet also admitted that criminal groups do not usually reach out to their victims either, which cuts both ways. That is the real tension in this story. A true white hat would not need to hold $320 million hostage while asking a company to patch its own bridge. But a thief hoping to launder stolen Bitcoin would not typically hand back 3,998.5 BTC and wait around for confirmation either. Until the funds actually move, calling this a rescue or a robbery is mostly a guess.
What This Means for Liquid Network and LBTC Holders
For now, LBTC holders are stuck waiting. Liquid is effectively frozen, exchanges have paused withdrawals, and the sidechain cannot process new transactions until the Federation finishes patching whatever flaw the hacker referenced. Traders who rely on Liquid for fast, private Bitcoin settlement between exchanges are the ones feeling this the most, since the network’s whole pitch is speed and confidentiality that regular Bitcoin transactions do not offer.
If the money comes back and the bug gets fixed quietly, this becomes a footnote in Bitcoin Layer 2 history. If it does not, Liquid joins a growing list of bridges that learned about their own weaknesses the hard way. Either way, Blockstream now has to prove that a sidechain can survive a $320 million stress test without losing user trust. So far, the hacker is still holding almost all of it.
Frequently Asked Questions
What happened to Liquid Network?
Someone withdrew about 4,000 BTC, worth roughly $320 million, from the Liquid Federation wallet using the SideSwap peg-out authorization key. Blockstream paused the sidechain’s bridge nodes and confirmed the withdrawal, while the party responsible claims to be a white-hat hacker planning to return the funds after a bug gets fixed.
Was the SideSwap key hacked?
No. Liquid said the SideSwap peg-out authorization key itself was not compromised and that no other keys on the network were put at risk. The key was simply used to authorize a transfer, which differs from a full custody breach where an attacker gains permanent control.
Is my LBTC safe right now?
Liquid paused bridge nodes, so no new transactions can move across the sidechain, and several exchanges have suspended LBTC deposits and withdrawals as a precaution. Other assets on Liquid, including USDT, DePix and real-world assets, were reportedly not affected by the withdrawal.
Are the Liquid Network hackers really white hats?
It is unclear. The hacker claims to be a white hat planning to return the funds once a bug is fixed. Ledger CTO Charles Guillemet is skeptical, noting real white hats rarely drain a bridge first, though he admits typical thieves don’t usually negotiate with victims either.
This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.

































so a federated sidechain with an 11-of-15 functionary set still had one signer key compromised through SideSwap, and we’re calling this white-hat because they gave it back? the peg-out surface has been the weak point since 2018 and nothing about that has actually changed
white-hat my ass, if you drain $320M without permission you’re a thief regardless of what you do after
reminds me of the Poly Network incident in 2021, same script, drain funds then negotiate a bounty and rebrand as ethical research