Self-proclaimed "white hat" hackers drain $320 million in bitcoin from Liquid reserves

September 7, 2026  09:14

About 4,000 bitcoins worth approximately $320 million were drained from the reserve wallet of Liquid Network, a bitcoin sidechain created by Blockstream. The attack is notable not only for its scale: preliminary data suggests that the attackers may have exploited a bug in the L-BTC issuance mechanism, after which the system itself deemed the operation valid and allowed real bitcoins to be withdrawn from the reserves, Bitcoin Magazine writes.

At the same time, the people behind the attack are not yet acting like typical cryptocurrency thieves. After withdrawing the funds, they left a message in the blockchain identifying themselves as "white hats"—ethical hackers who supposedly discovered a vulnerability.

Almost everything vanished from the reserve

Liquid Network operates as a bitcoin sidechain, enabling the issuance of tokenized L-BTC, whose value is backed by actual BTC on the main Bitcoin network. Reserve bitcoins are stored in a wallet controlled by the Liquid federation.

A multisignature scheme is used to execute reserve operations: at least 11 out of the 15 federation members must confirm a transaction. Prior to the attack, there were over 4,200 BTC in the reserve. Following the withdrawal, according to Blockstream’s proof-of-reserves page, slightly over 207 BTC remained.

The transaction that initiated the attack drained 4,019.4 BTC from the reserve address. According to preliminary findings, the attackers first minted over 4,000 L-BTC on the Liquid side, which were not actually backed by an equivalent amount of bitcoins in the reserve, and then swapped them for real BTC on the main network.

This exact moment may be the key to understanding the entire attack.

A vulnerability might have tricked the system into "believing" in non-existent bitcoins

It is assumed that the attackers took advantage of a bug related to the L-BTC issuance mechanism. In other words, this may not have been a classic breach of an individual crypto wallet, but an attack on the operational logic of the sidechain itself.

If this version is confirmed, an unusual sequence occurred: the system may have mistaken the L-BTC generated by the attackers for real ones, enabling them to withdraw actual BTC against them from the federated reserve.

The transaction was executed using a withdrawal authorization key associated with SideSwap, an exchange and Liquid Federation member. However, the exact attack vector has not been officially confirmed yet, so drawing definitive conclusions about the cause is premature.

Particularly critical is that, according to initial reports, the Hardware Security Module (HSM) servers protecting the federation members' keys signed the transaction. This means it is likely not a simple case of stolen keys. If the operation appeared valid to the protocol, the system itself may have processed it through its built-in confirmation routine.

This is precisely why a potential code bug is far more serious than a standard single-wallet breach: the flaw may reside within the very mechanism designed to determine which operations are legitimate.

Hackers left a message after withdrawing the funds

After obtaining the 4,019.4 BTC, the funds were moved to another address. Almost immediately after, a message was posted on the blockchain using the OP_RETURN field, stating: "we are white hats. contact us on blockchain."

This message adds a major twist to the attack. It remains unknown whether the attackers genuinely intend to return the funds or are merely using the term "white hats" to reframe theft as security research.

Later, a small transaction containing a message was sent to the hackers' address, asking them to contact Blockstream via the company's security email. It is assumed the sender was a Blockstream representative, though this remains unconfirmed.

Another message that surfaced later urged contact via Signal. However, its origin is doubtful and not necessarily tied to the holders of the stolen bitcoins.

Meanwhile, according to available data, the 4,000 BTC remained at the address to which they were transferred immediately after the drain.

Liquid halts L-BTC operations

Following the incident, Liquid Network suspended bridge nodes, and crypto exchanges were advised to temporarily pause L-BTC deposits and withdrawals.

The sidechain itself continued to produce blocks, but access was restricted. Other assets issued on Liquid—including USDT, DePix, and tokenized real-world assets—were not directly affected, according to a statement from the network.

This distinction is key to understanding the scope of the problem: the issue primarily involves the backing mechanism for L-BTC, rather than a full shutdown of the entire network.

Nevertheless, for L-BTC holders, the situation remains critical. While underlying BTC withdrawals from reserves are frozen, L-BTC holders are essentially unable to redeem their tokens for bitcoin.

Number of affected users remains unknown

Determining the exact scale of potential user damage is difficult. Liquid is a relatively closed system, leaving little public data on how L-BTC is distributed among retail users, companies, and Blockstream entities.

Consequently, it is unclear what portion of active L-BTC belongs to everyday users versus major market players.

If the stolen bitcoins are not recovered, the impact will depend not only on the $320 million sum, but also on how many circulating L-BTC tokens are now undercollateralized.

This makes the current event a severe test for the Liquid model: trust in the sidechain relies entirely on the premise that every L-BTC is backed by a bitcoin in reserve.

Will the bitcoins be returned?

There is no definitive answer yet, but the nature of the incident leaves room for an unusual outcome.

If the attackers truly consider themselves "white hats" aiming to expose a critical flaw, they might request a bug bounty and return the vast majority of the funds. This pattern has occurred before in crypto: a bug is demonstrated via a controlled attack, followed by negotiations and asset recovery.

However, given the enormous sum, an outright theft is also plausible. Offloading and laundering thousands of bitcoins is vastly more complex than moving them to a new wallet: high-volume transactions remain visible on the public blockchain, and subsequent movements can be closely tracked.

For now, Liquid Network remains in limbo—balancing efforts to pinpoint the precise exploit vector with potential communications with those holding the drained funds.

The central question is no longer just who stole the $320 million, but why a system secured by an 11-of-15 multisig federation processed the operation in the first place.

Follow NEWS.am Tech on Facebook and Twitter