The Bitcoin-linked Layer 2 scaling network Liquid Network suffered a major security breach when bad actors drained approximately 4,000 Bitcoin, valued at roughly $320 million, from the Liquid Federation wallet, according to a public statement issued on X by the network on Sunday. The heist stripped the platform of nearly its entire balance, leaving it with just a fraction of the roughly 4,200 BTC it held prior to the incident.
Blockstream’s Transaction Layer Targeted
Founded in 2018 by blockchain technology firm Blockstream, Liquid Network serves as a transaction acceleration layer for cryptocurrency exchanges. Because congestion frequently slows down the primary Bitcoin blockchain, exchanges use Liquid to speed up processing by locking actual Bitcoin (BTC) in exchange for issued Liquid Bitcoin (L-BTC). The platform confirmed that the compromised funds moved out through the SideSwap PAK, an authorized withdrawal settlement platform for the network. However, Liquid Network stated that the SideSwap key itself was not compromised, nor were other protocol keys.
https://x.com/Liquid_BTC/status/2096696272447218108
How the 4,000 L-BTC Exploit Unfolded
According to tracking data from blockchain portal Cryptoticker.io, the exploit unfolded through a seemingly standard transaction at 12:05 PM CEST, when a user sent 4,000 L-BTC to the SideSwap peg-out service. Because SideSwap sits within the Liquid Federation as a normal route to convert L-BTC back into native Bitcoin, the system processed the order routinely: the L-BTC tokens were burned on Liquid, a valid peg-out authorization was generated, and 23 minutes later the Federation paid out roughly 3,996 BTC on the Bitcoin mainchain. Nothing about the transfer flagged as suspicious to operators at the time.
Exchanges Suspend L-BTC Deposits and Withdrawals
Following the breach, connected cryptocurrency exchanges immediately suspended deposits and withdrawals of L-BTC linked to Liquid Network. Other assets running on the sidechain—including USDT, DePix, and real-world asset tokens—remain unaffected by the security incident, as does the main Bitcoin blockchain itself. Analysts and reports point the root cause toward a software vulnerability inside Elements, the open-source code base that powers Liquid, rather than any flaw in Bitcoin’s core architecture.
Bridge Nodes Disabled Amid White-Hat Claims
Liquid Network responded by pausing the Liquid sidechain entirely while engineers work to resolve the vulnerability. Bridge nodes have been temporarily disabled to prevent any new transactions from reaching the network, and operators have apologized for the disruption while working to restore normal operations. Cryptoticker.io reported that the attacker attached a message to an on-chain Bitcoin transaction identifying themselves as a white-hat hacker who intends to return the majority of the funds once the underlying bug is patched and all nodes are updated. Both sides are currently negotiating the return of the assets, and the platform’s status remains paused as developers deploy fixes.

Related reading