Liquid Freezes Bridge After 4,000 BTC Withdrawal; Purported ‘White Hats’ Hold 95% and Condition Return on Patch
Liquid, the Bitcoin sidechain, paused operations after actors claiming to be white‑hat hackers withdrew about 4,000 BTC (roughly $320 million) from its federation wallet, according to a network update.
Bridge paused; exchanges restrict L‑BTC
Liquid said it disabled bridge nodes, preventing new transactions. The network added that exchanges had halted or were preparing to halt L‑BTC deposits and withdrawals. Other assets issued on Liquid — including USDT, DePix, and certain real‑world assets — were unaffected, according to the network.
What’s at stake: 95% of a ~4,200 BTC wallet
The withdrawal represented roughly 95% of the wallet’s approximately 4,200 BTC balance, per the source report. Liquid uses Bitcoin held by its federation to back L‑BTC on the sidechain, leaving most of the wallet’s BTC under the actors’ control until funds are returned.
On‑chain back‑and‑forth with Blockstream
Blockstream, Liquid’s technology provider, contacted the actors through signed on‑chain messages, according to the source. In an X post compiling those public, transaction‑embedded messages, JAN3 CEO and former Blockstream executive Samson Mow described a timeline that began at 11:30 a.m. Pacific time, when the actors identified themselves as white hats and requested on‑chain contact.
Mow said Blockstream replied about an hour later, directing the actors to its security email and sending a PGP‑encrypted message. Hours after that, the actors asked if they could return most of the Bitcoin to a Blockstream address, then demanded the vulnerability be fixed and every node updated before transferring funds. One Blockstream reply read, “Yes, thank you.” Mow said that response addressed the return‑address question, not the patching condition.
As of 9:12 p.m. Pacific time, about 3,998.5 BTC remained unmoved, with no further on‑chain messages observed in Mow’s compilation.
SideSwap: peg‑out ran as customer order; Elements bug blamed
SideSwap said the withdrawal passed through its peg‑out service as a customer order using its Peg‑out Authorization Key (PAK), but said the key was not compromised. SideSwap said the L‑BTC used in the transaction originated from a bug in Elements — the open‑source software underpinning Liquid — rather than SideSwap’s own systems.