Community Trust ScoreVerified
Roughly $320 million walked out of the Liquid Federation wallet in a single weekend. And the network still can’t fully explain how.
On Sunday, actors described as “purported white-hat hackers” pulled approximately 4,000 BTC from the Liquid Federation wallet, targeting a component called the Peg-out Authorisation Key — the mechanism managed by the SideSwap platform that handles Bitcoin conversion within the network. Liquid Network moved fast to contain it, disabling bridge nodes almost immediately to stop further transactions from going through. Exchanges got word quickly and suspended L-BTC deposits and withdrawals. Other assets on the network — USDT and DePix — were reportedly unaffected, though the node shutdown did pause transactions involving those too.
Not compromised. That’s what Liquid Network said about its federation keys.
How 4,000 BTC Left the Building
The federation’s own keys stayed intact, per the network’s account. A software vulnerability in the L-BTC issuance and redemption process seems to be the real culprit — one that apparently allowed the creation of unbacked L-BTC, which was then used to trigger the peg-out and drain the reserve. So the keys weren’t stolen. The process itself was gamed. That’s a meaningful distinction, and probably a more unsettling one for anyone trying to assess the network’s architecture going forward.
The reserve backing the L-BTC peg was basically gutted. Of the 4,200 BTC sitting in that wallet, 4,000 walked out. That left the peg — which is supposed to be a clean 1:1 relationship between L-BTC and Bitcoin — critically exposed. Federated systems live and die by that kind of trust, and with 95% of the reserve gone in one move, the network’s credibility took a serious hit.
Comparisons to past bridge disasters came fast. The 2022 Wormhole breach and Nomad’s message-verification failure both involved unbacked wrapped assets — situations where the underlying reserves didn’t match the tokens circulating on the other side. Liquid’s incident fits that pattern pretty closely. Cross-chain bridges and federated peg mechanisms have been a consistent weak point across the industry, and this isn’t the first time a software-level flaw rather than a direct key compromise caused the damage.
Partial Return, Big Questions
The actors did come back. In an unexpected move, they returned 3,400 BTC to the Liquid Federation address, with the transaction going through at Bitcoin block 965,950. Messages were exchanged with Blockstream during the process. It’s unclear what exactly was said, and the source didn’t specify the content of those on-chain communications.
But 598.5 BTC — worth roughly $47 million — stayed with the actors as of September 7. No confirmation of further repayment. No timeline. The claim, apparently, was that the funds might be returned once the flaw was patched. That hadn’t happened yet.
And Liquid Network still hasn’t put out a full technical post-mortem. That’s the part that’s probably frustrating stakeholders most. Without a detailed breakdown of exactly what was exploited, how it was exploited, and what’s being done to close it, the community is left guessing. Speculation fills the gap. And in crypto, that gap tends to grow fast.
Bridge nodes remain inactive. L-BTC transactions are still on hold. The network’s operational capacity is significantly reduced, and exchanges are sitting on suspended withdrawal and deposit functions with no clear restart date disclosed as of the reporting cutoff.
What’s Still Broken
The Peg-out Authorisation Key sits at the center of this whole thing. It’s the piece that makes the Bitcoin conversion process work — the mechanism SideSwap manages on behalf of the federation. It wasn’t cracked open by a private key theft, but it was effectively weaponized through a flaw in the software layer. That’s a harder problem to solve than a simple key rotation. It means the vulnerability was structural, baked into the issuance and redemption logic itself.
Federation members acted quickly once the withdrawal hit. The response — disabling nodes, alerting exchanges, halting L-BTC movement — was fast. But fast containment doesn’t answer the deeper question of how a 4,000 BTC drain was possible in the first place, or whether other vectors exist in the same codebase.
The partial return is genuinely unusual. White-hat actors returning funds after demonstrating a vulnerability isn’t unheard of in crypto, but the scale here — and the fact that nearly 600 BTC worth $47 million hasn’t come back — makes the “white-hat” framing complicated. Whether the remaining funds get returned, and under what conditions, is still wide open.
Stakeholders are waiting. Exchanges are waiting. The network’s bridge nodes are still down, L-BTC remains frozen, and the 598.5 BTC gap sits unresolved at Bitcoin block 965,950.
Frequently Asked Questions
How much Bitcoin was withdrawn from the Liquid Federation wallet?
Approximately 4,000 BTC, valued at around $320 million, was withdrawn from the Liquid Federation wallet, leaving only about 200 BTC of the original 4,200 BTC reserve intact.
How much of the stolen Bitcoin has been returned?
The actors returned 3,400 BTC to the Liquid Federation address via Bitcoin block 965,950, but approximately 598.5 BTC — worth roughly $47 million — had not been returned as of September 7.
Why It Matters
The security breach of Liquid Network, resulting in the loss of approximately 4,000 BTC, underscores significant vulnerabilities within decentralized finance platforms, particularly those managing large sums of cryptocurrency. This incident raises concerns among investors and users about the robustness of security measures in place, potentially impacting confidence in similar networks and their operational integrity. As the crypto market continues to evolve, such breaches may influence regulatory scrutiny and prompt platforms to enhance their security protocols to protect user assets and maintain trust.





