Bitcoin sidechain Liquid paused operations on Sunday after actors identifying themselves as white-hat hackers withdrew approximately 4,000 Bitcoin worth $320 million from its federation wallet. The Liquid Bitcoin sidechain hack represented roughly 95% of the wallet’s total balance of approximately 4,200 BTC. Bridge nodes were disabled following the withdrawal, halting new transactions, while exchanges suspended or prepared to suspend L-BTC deposits and withdrawals. Other assets on the network including USDT, DePix and real-world assets were reported as unaffected.
Blockstream, Liquid’s technology provider, made contact with the actors through signed onchain messages. The actors said they would return most of the Bitcoin after the vulnerability was patched and every node had installed the update. At the time of writing, the funds had not been returned.
SideSwap confirmed the withdrawal passed through its peg-out service as a customer order using its Peg-out Authorization Key, but said the key itself was not compromised. The firm attributed the vulnerability to a bug in Elements, the open-source software that underpins Liquid, rather than any flaw in SideSwap’s own systems.
A Timeline Pieced Together Onchain
Jan3 CEO and former Blockstream chief strategy officer Samson Mow compiled a detailed public timeline of the exchange, reconstructed from messages embedded in Bitcoin transactions. The actors identified themselves as white hats at 11:30 am Pacific time and requested onchain contact. Blockstream responded approximately an hour later, directing them to its security email before sending a PGP-encrypted message.
Hours later, the actors asked whether they could return most of the Bitcoin to a Blockstream address and demanded the vulnerability be fixed and every node updated before transferring the funds back. Blockstream replied “Yes, thank you,” though Mow noted the response addressed the return address question rather than the patching condition. Around 3,998.5 BTC remained unmoved as of 9:12 pm Pacific time, with no further messages exchanged.
Liquid Bitcoin Sidechain Hack Exposes Federation Model Risks
I want to be direct about what this event reveals, because I think the white-hat framing risks obscuring the more important underlying story. Whether or not these actors return every Bitcoin, a bug in open-source software underpinning Liquid allowed a single transaction, processed through a legitimate peg-out service, to drain 95% of the federation wallet. That is a critical infrastructure failure that only avoided becoming a catastrophe because the people who found it chose to identify themselves rather than disappear.
Liquid’s federation model has always been its central trust assumption. It secures Bitcoin through a group of functionaries rather than through cryptographic consensus alone, which introduces the kind of coordinated vulnerability that pure on-chain systems avoid by design. I have seen this pattern before in crypto, a bridge or sidechain presents itself as a mature, production-ready layer, attracts real capital, and then reveals through a hack or exploit that the security model had assumptions baked into it that were never properly stress-tested at scale. The funds may well be returned. The vulnerability may be patched cleanly. But federations holding hundreds of millions in Bitcoin need to be held to a higher security standard than an open-source bug fix and a polite onchain exchange can provide.

