Liquid Network Pauses After $320 Million Bitcoin Reserve Exploit
A bug in Blockstream's Elements software allowed 'white-hat' hackers to withdraw 3,996 BTC from the sidechain's federation wallet.
The Liquid Network has paused its operations following the unauthorized withdrawal of approximately $320 million in Bitcoin from its federation reserve wallet. The incident has triggered an immediate freeze of the sidechain as developers work to secure the system.
According to reports from Cointelegraph and TechNadu, 3,996 BTC was paid out from the Liquid Federation wallet. The exploit was executed via the peg-out service of SideSwap and has been attributed to a software bug within Elements, the protocol developed by Blockstream. The individuals responsible for the withdrawal have claimed to be "white-hat" hackers, asserting that their intentions were benevolent and pledging to return the funds once the vulnerability is officially patched.
The Role of the Liquid Network
Liquid Network operates as a Bitcoin sidechain designed to serve as a settlement layer for institutional players and cryptocurrency exchanges. By utilizing a federated model—where a select group of entities manages the reserves that back the L-BTC token—the network provides faster and more confidential transactions than the primary Bitcoin blockchain. This architecture is intended to streamline high-volume movements of assets while maintaining a link to the security of the main chain.
Implications for Federated Systems
This exploit exposes a critical vulnerability in the software powering one of Bitcoin's most prominent sidechains. Because the stability of L-BTC depends entirely on the reserves held by the federation to maintain its peg, the sudden removal of nearly 4,000 BTC creates a significant liquidity risk. The event undermines confidence in federated settlement layers, demonstrating that even institutional-grade infrastructure can be compromised by a single software flaw.
Recovery and Next Steps
The current focus remains on the patching of the Elements software and the subsequent recovery of the reserves. While the actors involved claim to be acting in the interest of network security, the industry is watching closely to see if the pledged funds are returned in full. Until the vulnerability is resolved and the reserves are restored, the network's operational status remains suspended, leaving users and institutions waiting for a formal restart.