BNB $750.10 -1.57%
XRP $1.41 -0.86%
ETH $2,505.29 +0.12%
BTC $79,949.96 +0.00%
BNB $750.10 -1.57%
XRP $1.41 -0.86%
ETH $2,505.29 +0.12%
BTC $79,949.96 +0.00%
BREAKING
Bitcoin News

Blockstream’s Liquid Network Suspended as 4,000 Bitcoin Bug Exposed, Draining $320 Million

Blockstream's Liquid Network Halts as 4,000 Bitcoin Bug Drains $320 Million
Blockstream's Liquid Network Halts as 4,000 Bitcoin Bug Drains $320 Million

Community Trust ScoreVerified

88%
Real
Verified8 votes
Updated 47 minutes ago

Blockstream pulled the plug on its Liquid Network Sunday. White hat hackers had just walked out with roughly 4,000 BTC — around $320 million — after finding and exploiting a bug buried inside the network’s Elements software.

The whole thing came to light through blockchain analyst Ergo BTC, who caught the withdrawal and flagged it publicly. From there, the crypto community basically lit up. The exploit is believed to have been carried out by ethical hackers — the kind who poke holes in systems specifically to stop bad actors from doing it first. That framing didn’t stop people from asking hard questions about what exactly happened and whether “ethical” is the right word here.

How the 4,000 BTC Left the Network

The sequence started simply enough. A customer moved 4,000 L-BTC to Sideswap’s peg-out service. The service processed it normally, burning the L-BTC on the Liquid sidechain the way it’s supposed to. At 14:28 UTC, the Liquid Federation paid out 3,996 BTC to the customer’s Bitcoin address. Clean, routine — except it wasn’t.

Advertisement

Blockstream later confirmed the L-BTC involved was created because of a bug in the Elements software. In other words, the coins that got pegged out shouldn’t have existed in the first place. The system burned tokens it had no business burning, and real BTC went out the door.

Exchanges got instructions to suspend L-BTC deposits and withdrawals immediately. No timeline was given for when that changes.

Ledger’s CTO Charles Guillemet wasn’t fully buying the white hat narrative. He pointed out that the hackers asked to be contacted on Signal — which isn’t exactly standard practice for ethical security researchers. Blockstream, for its part, reached out through an OP_RETURN message embedded in the blockchain, asking the hackers to get in touch via its security email. Whether they’ve responded isn’t clear yet.

Samson Mow, Confidential Transactions, and the AI Question

Samson Mow, CEO of JAN3, weighed in pretty quickly. He said the problem seems tied to Liquid’s Confidential Transactions feature, though developers haven’t confirmed that. He also noted the vulnerability sits at the node level — not in PAKs or HSMs, which are the hardware-security components. That’s a meaningful distinction for people running Liquid infrastructure.

JAN3’s own Aqua Wallet has Liquid functionality, and Mow said that’s affected. Standard Bitcoin transactions through the wallet, though, are fine.

The community’s response ranged from concerned to furious. Some called for the Elements software to be pulled entirely. That’s a drastic ask, but it gives you a sense of how rattled people are. Liquid is a federated sidechain — it’s supposed to be one of the more governed, stable environments in the Bitcoin ecosystem. Having it go down for manual intervention is not a great look.

There’s also a weird thread running through the discussion: speculation that AI, or specifically Large Language Models, might have been the tool that found the bug. Blockstream hasn’t said anything about how the vulnerability was discovered, so that’s still just speculation. But it’s the kind of speculation that tends to stick around when no one fills in the blanks.

What Blockstream Is Doing Now

Blockstream is working to get the network back up. The immediate priority is re-establishing contact with the white hats to understand exactly what they did and how. That knowledge matters — you can’t patch what you don’t fully understand.

The technical teams are going through node-level operations carefully, trying to isolate whatever triggered the bug without disturbing PAKs or HSMs. That work is ongoing. No resolution date has been announced.

The financial picture is uncomfortable. Four thousand BTC is not a rounding error. It’s a number that makes institutional stakeholders nervous, especially ones who’ve been using Liquid precisely because it’s supposed to be secure and well-governed. A federated model implies multiple parties watching the system — which makes it harder to explain how something this big slipped through.

Sidechain technology has always carried a certain amount of skepticism from the broader Bitcoin community. Incidents like this don’t help. The argument for sidechains is that they extend Bitcoin’s functionality without touching the base layer. The counterargument, which gets louder after events like Sunday’s, is that every layer you add is another surface for something to go wrong.

Blockstream’s handling of what comes next will probably matter as much as the exploit itself. How fast can they patch? Can they actually get the white hats talking? Will they publish a full post-mortem? Those answers will shape how the community reads the whole episode.

For now, L-BTC transactions stay frozen. The Liquid Federation is in manual mode. And somewhere out there, a group of hackers is sitting on Signal, waiting to see if Blockstream’s outreach goes anywhere.

Frequently Asked Questions

What caused the Liquid Network to pause operations?

Blockstream paused the Liquid Network after white hat hackers exploited a bug in its Elements software, resulting in the withdrawal of 4,000 BTC worth roughly $320 million from the network.

Is Samson Mow’s Aqua Wallet affected by the Liquid Network bug?

Yes, according to Mow, the Liquid functionality inside JAN3’s Aqua Wallet is impacted, though he said standard Bitcoin transactions through the wallet remain unaffected.

Why It Matters

The halt of Blockstream's Liquid Network due to the exploitation of a significant bug underscores the vulnerabilities present in even established decentralized networks. This incident not only raises concerns about the security protocols in place for handling large volumes of cryptocurrency but also highlights the critical role of ethical hackers in identifying and mitigating risks within the blockchain ecosystem. As the market continues to evolve, such security breaches could impact investor confidence and regulatory scrutiny surrounding cryptocurrency platforms.

Community Trust IndexModerate Confidence
88%
Real
Real88%13%Fake
8 community signals

Steven Anderson

Steven is a technology-focused writer with a strong interest in emerging digital trends and innovation. With experience spanning both travel and online projects, he brings a global perspective to his reporting and analysis. His work reflects a practical understanding of how technology, markets, and digital platforms intersect, offering readers clear insights into developments shaping the modern tech and crypto landscape.

Advertisement

Related Stories