4,000 BTC Withdrawn from Liquid: Was Bitcoin Hacked?

Over the past few hours, an incident has sent shockwaves through the ecosystem: ~4,000 BTC (worth nearly $320M and representing ~95% of Liquid’s reserves) were drained from the Liquid Network federation wallet. Liquid subsequently halted bridge nodes and suspended transaction processing.

Before the panic spreads, one fundamental distinction must be made: Bitcoin itself was not hacked.

And that is probably the most important thing to understand about this incident.

What is Liquid Network?

Liquid is a federated sidechain built around Bitcoin and developed by Blockstream. The concept is simple: Bitcoin is deposited into an infrastructure controlled by a federation (using an 11-of-15 multisig model) and represented on Liquid as L-BTC, with the goal of maintaining a 1:1 reserve peg.

This allows users to benefit from faster, more confidential transactions. But it also introduces another layer of trust and complexity.

What actually happened?

Initial analysis indicates that neither the private keys nor the SideSwap Peg-out Authorization Keys (PAKs) were compromised. This was not a classic private key theft.

Instead, the incident stems from a software vulnerability in the underlying open-source software, Elements. This exploit allowed unbacked L-BTC to be minted, processed through the peg-out mechanism, and ultimately transferred to a mainnet Bitcoin address.

Note that only the Bitcoin backing L-BTC was targeted—other assets issued on Liquid (like USDT or RWAs) remained completely unaffected.

Are they really “White Hats”?

The attackers left an OP_RETURN message directly on the Bitcoin mainchain claiming to be “white-hat hackers.” They provided encrypted details about the vulnerability to Blockstream and stated they are willing to return most of the funds—on the condition that 100% of the federation nodes are patched first.

While this sounds promising, caution is necessary. Calling oneself a white hat on-chain does not guarantee funds will be returned. Until the BTC is back in the federation’s reserves, this remains an ongoing crisis.

So why say Bitcoin wasn’t hacked?

Because Bitcoin and Liquid are entirely different entities:

  • Protocol integrity: Bitcoin’s base layer, consensus mechanism, and Proof of Work remained 100% operational and untouched.

  • Infrastructure vs. Protocol: The issue occurred within a secondary software stack built around Bitcoin, not within Bitcoin itself.

  • On-chain transparency: The entire investigation, fund movement, and communication are happening publicly on the Bitcoin blockchain for anyone to verify.

Self-custody and the trade-offs of secondary layers

We often repeat “Not your keys, not your coins,” but this principle extends beyond centralized exchanges. Every time we add sidechains, bridges, federations, or complex multisigs, we introduce new potential points of failure.

This doesn’t mean solutions like Liquid or Lightning are bad. Sidechains provide functionality that Bitcoin’s base layer was never designed to prioritize. But we must be clear about the trade-offs.

The takeaway isn’t “never use Liquid.” The better question is: Do I actually understand the trust model, software stack, and risks of the secondary layers I use?

What to take from this

When a headline reads “Bitcoin was hacked and $320 million was stolen,” the natural reaction for newcomers is to think Bitcoin isn’t secure.

Reality is more nuanced: an infrastructure built around Bitcoin suffered a software flaw. Bitcoin gave us financial sovereignty, but sovereignty requires continuous learning, verifying, and understanding where we put our funds.

The situation is still unfolding. I’ll be watching closely to see if the funds are fully returned and how the ecosystem learns from this event.

Stay humble. Stay curious. Keep learning. 🟠

Write a comment