← Back to news
Sep 7, 2026

$320M Out the Front Door: The Liquid Network Hack and the Trouble With "White Hats"

$320M Out the Front Door: The Liquid Network Hack and the Trouble With "White Hats"
Illustration created with AI

On 6 September, the Liquid Network — a Bitcoin sidechain operated by Blockstream and a federation of exchanges and companies — halted after roughly 4,000 BTC (about $320 million) left its federation wallet, leaving only a couple of hundred behind.

How Liquid is supposed to work

Liquid is a "sidechain." You lock real Bitcoin with the federation (a peg-in) and receive an equal amount of L-BTC on Liquid, which settles faster and supports some features Bitcoin's base layer doesn't. To exit, you burn L-BTC and the federation releases the corresponding real Bitcoin back to you (a peg-out). The whole model depends on the federation holding one real BTC in reserve for every L-BTC in circulation.

What went wrong

According to Blockstream, this was not a stolen key. A customer sent 4,000 L-BTC to an approved peg-out service run by a federation member. The L-BTC was burned with a valid authorization, and 23 minutes later the federation paid out almost 4,000 real BTC on the main chain — as designed. The flaw was in the sidechain software (Elements): it accepted as legitimate a peg-out that should not have been. The front door worked exactly as built; the lock was miscut.

This is a different failure mode from the DeFi oracle hacks of recent weeks. There, attackers fool a price feed. Here, a trusted federated system mis-validated its own core operation.

The "white hat" question

The group left an on-chain note: "we are whitehats. contact us on chain," and has reportedly offered to return most of the funds once the bug is fixed. Take that at face value and it is a security researcher doing responsible disclosure the hard way. Read it less charitably and it is a $320 million hostage negotiation with a polite cover letter. The industry has seen both, and they look identical in the first 48 hours. What matters is the final settlement: how much comes back, how fast, and whether any "bounty" retained is proportionate to a disclosed bug or just a ransom by another name.

The takeaway

Wrapped and bridged Bitcoin — L-BTC, and every other "BTC on another chain" — carries the risk of whatever system is holding the real coins. A federation is more accountable than an anonymous multisig — its members are known companies — but the reserve still emptied through an approved channel in under half an hour, and how the shortfall is ultimately made whole was still unsettled at the time of writing. If you hold bridged BTC anywhere, the operator's security record is part of what you own.

This article is general commentary for information only and is not investment or security advice.