Blockstream's Liquid Network Loses $47 Million After 'White Hat' Exploit
Attackers drained $320 million from a Bitcoin sidechain before returning a portion of the funds in a disputed bounty negotiation.
A software vulnerability in the Liquid Network allowed attackers to drain approximately 4,000 BTC, valued at $320 million, from the federation's reserve wallet in September 2026. The incident has sparked a heated debate over the line between ethical hacking and extortion after the attackers kept a significant portion of the funds.
The exploit occurred when attackers leveraged a bug in the network's software to create unbacked L-BTC. These synthetic assets were then "pegged out" into actual Bitcoin via SideSwap, allowing the perpetrators to withdraw the funds from the federation's reserve. Following the theft, the attackers claimed to be "white hats" and initiated negotiations with Blockstream, the network's developer. These communications were conducted via PGP-encrypted messages embedded directly into Bitcoin transactions using the OP_RETURN field.
The Federation Model
The Liquid Network operates as a Bitcoin sidechain designed for faster and more private transactions. Users lock BTC in a federation-controlled wallet to receive L-BTC. The system is managed by a federation of over 80 members, though the core functionaries are operated by 15 entities. The reserves are secured by an 11-of-15 multisig wallet, a structure intended to ensure that no single party can compromise the funds.
Security and Trust Implications
Despite the multisig protections, the software bug bypassed these safeguards, raising concerns about "decentralization theater." Critics argue that if a single party's code update can enable the theft of federation funds, the perceived security of the distributed model is illusory. Alena Vránová, founder of Gart, characterized the event as criminal rather than ethical, stating, "If you exploit vuln, steal 4k BTC and demand a fix for ransom, that’s EXTORTION."
The Aftermath
After Blockstream patched the vulnerability, the attackers returned 3,400 BTC. However, they retained 598.5 BTC—roughly 15% of the initial haul—which is valued at approximately $47 million. The attackers presented this remaining amount as a bounty for discovering the flaw, but Blockstream has refused to acknowledge the payment as a legitimate reward, viewing it instead as a ransom. It remains unclear whether the remaining funds will be recovered or if the incident will prompt a fundamental redesign of the Liquid Network's security architecture.