Alleged White-Hat Actors Withdraw $320M in Bitcoin from Liquid Sidechain
Preface
Summary: Blockstream's Liquid sidechain was paused after roughly 4,000 BTC — about $320 million — left the federation wallet that anchors all L-BTC. This article summarizes what happened, the chain of events, and the dialogue between Liquid, Blockstream and the actors who removed the funds. It lays out the technical context, reported timelines, and the responses from involved parties. The goal is to provide a clear, factual account without speculation, emphasizing the importance of the reported vulnerability in Elements and the operational actions taken by federation members.
Lazy bag
Key takeaways: The Liquid federation paused its sidechain after about 4,000 BTC was withdrawn. The withdrawal used SideSwap's peg-out authorization key, which Liquid says was not compromised; both SideSwap and Blockstream point to a bug in Elements. The actors called themselves white-hat and requested the bug be patched before returning most funds.
Main Body
On Sunday, Blockstream's Liquid sidechain was paused after a significant outflow from the federation wallet that backs L-BTC. Approximately 4,000 BTC — valued at about $320 million at the time — were withdrawn from the wallet that underwrites every L-BTC in circulation. The event prompted an immediate operational response: Liquid disabled its bridge nodes and began communicating publicly about the incident while Blockstream reached out to the actors on-chain.
The sequence of events, as reported by federation member SideSwap, began when a customer sent 4,000 L-BTC to SideSwap's peg-out service at 14:05 UTC. SideSwap said it burned those L-BTC tokens under a valid authorization. Roughly 23 minutes later, the federation processed a peg-out and paid out 3,996 BTC. Liquid's public messaging acknowledged a security incident and indicated that purported white-hat actors had withdrawn the funds. Blockstream engaged with the actors by exchanging signed messages embedded in Bitcoin transactions.
Liquid has stated that the funds moved by using SideSwap's peg-out authorization key, but emphasized that the peg-out key itself — and no federation key — appears to have been compromised. SideSwap likewise reported no breach of its systems and suggested the issue stems from a bug in Elements, the open-source software that Liquid runs on. Blockstream has not publicly disclosed the precise nature of the bug. Notably, a fix addressing the vulnerability had been merged into Elements about five weeks prior to the incident, according to statements, but the chain remained vulnerable at the patch level used by Liquid.
Technical analysis from observers indicates that the incident was not a simple key theft. Instead, someone appears to have created L-BTC tokens without corresponding Bitcoin backing — effectively minting sidechain tokens — and then redeemed them through a peg-out flow that appeared legitimate. That distinction matters because it suggests a protocol-level or implementation bug allowed unauthorized issuance of L-BTC, rather than a stolen private key being used directly to sign an otherwise normal peg-out.
Before the incident, the federation wallet held roughly 4,200 BTC; after the peg-out, it held around 200 BTC. Other assets on Liquid — including USDT, DePix and various tokenized real-world assets — were reportedly untouched. Bitcoin's mainnet and its consensus remained unaffected; this event pertains to the Liquid sidechain's federation and Elements software.
The on-chain communications from the actors included a message stating, "we are whitehats. contact us on chain." Blockstream responded with an email address about an hour later, and the two parties exchanged PGP-signed messages embedded in Bitcoin transactions. According to published excerpts, the actors offered to return most of the funds on the condition that the underlying bug be patched first and that all nodes be updated, arguing that the chain was still vulnerable at the latest commit. Blockstream accepted the condition publicly in a signed response included in the same block as the actors' messages.
Commentary from industry figures was mixed. Charles Guillemet, CTO of Ledger, initially questioned whether draining a bridge fits white-hat norms, citing past bridge exploits such as Ronin and Euler. He later noted that practices may be changing and warned against a new model where actors take funds first and demand a patch before returning them. Samson Mow, formerly Blockstream's head of security, released a timeline and estimated the actors' address held about 3,998.5 BTC after the events he tracked.
Liquid's pause of the sidechain and the public, on-chain negotiation underscore several operational risks for federated sidechains: the importance of timely software updates across all federation members, the consequences of implementation-level bugs, and the complexity of coordinating responses across multiple organizations. Even when keys and individual operator systems are not directly compromised, weaknesses in the underlying protocol or reference implementation can enable large-scale unauthorized movements.
For users and custodians, the incident highlights the need for robust risk management when relying on federated systems: monitoring for software updates, validating the integrity of distributed software, and maintaining contingency procedures for pausing or isolating bridges and peg mechanisms. For developers, the episode is a reminder that patches must be deployed promptly across the entire network footprint to reduce exposure.
Blockstream and Liquid have been engaged in communication with the actors and the broader community while the incident is being investigated and remediated. The long-term implications will depend on the extent to which the actors return funds, the final technical root cause that Blockstream and Elements maintainers disclose, and how federation members change their update and operational practices going forward. At the time of reporting, efforts were focused on securing the sidechain, coordinating a patch rollout, and recovering or isolating the remaining funds.
Key Insights Table
| Aspect | Description |
|---|---|
| Key Fact 1 | Approximately 4,000 BTC (~$320M) were withdrawn from the Liquid federation wallet using a peg-out that appeared valid. |
| Key Fact 2 | Liquid and SideSwap say the withdrawal used SideSwap's peg-out key but that the key itself wasn’t breached; they point to a bug in Elements allowing unauthorized creation and peg-out of L-BTC. |
| Key Fact 3 | The actors claim to be white-hat and demanded the bug be patched before returning most funds; communications occurred on-chain via signed messages. |
| Key Fact 4 | The wallet balance fell from ~4,200 BTC to ~200 BTC. Other Liquid assets and Bitcoin mainnet were not reported as affected. |
| Key Fact 5 | The incident highlights risks in federated sidechains: timely patching, coordinated updates, and robustness of reference implementations. |