Liquid Network Pauses Sidechain After $320 Million Bitcoin Security Incident
A bug in Elements software allowed actors to withdraw 4,000 BTC from the federation wallet via SideSwap.
The Liquid Network has paused its sidechain and disabled bridge nodes following a security incident that saw approximately 4,000 BTC leave its federation wallet. The withdrawal, valued at roughly $320 million, triggered an emergency response to protect the collateral backing the network's native asset.
The incident occurred when actors, claiming to be white-hat hackers, utilized SideSwap's peg-out service to withdraw the funds. The federation wallet's balance plummeted from approximately 4,200 BTC to around 200 BTC, meaning roughly 95% of the reserves were removed. While the exploit involved the SideSwap Peg-out Authorization Key (PAK), both SideSwap and Liquid confirmed that the key itself was not compromised.
The Technical Failure
The vulnerability stemmed from a bug in Elements, the open-source software powering the Liquid Network. Specifically, the breach was made possible by a cache bug in the validation of confidential transactions. Liquid operates as a Bitcoin sidechain and settlement layer designed to allow exchanges to facilitate faster and cheaper transactions. To maintain the value of L-BTC, the network relies on a federation of nodes to hold actual Bitcoin in a secure federation wallet.
In the immediate aftermath, Liquid notified exchanges to halt all LBTC deposits and withdrawals to prevent further instability. Despite the scale of the Bitcoin withdrawal, the network confirmed that other assets—including USDT, DePix, and various real-world assets (RWAs)—remained unaffected by the exploit.
Industry Implications
This event exposes a critical vulnerability in the peg-out mechanism of Bitcoin sidechains, raising questions about the reliability of the Elements software. Because the federation wallet serves as the primary collateral for L-BTC, a permanent loss of these funds would have fundamentally undermined the asset's peg. The incident serves as a stark reminder that even established settlement layers are susceptible to low-level software bugs that can bypass high-level security keys.
Path to Recovery
The actors behind the withdrawal have entered negotiations to return the funds, but they have imposed specific conditions. The hackers requested that Blockstream, the network's primary technology provider, fix the vulnerability first. They warned that the chain remained at risk under the latest commit and insisted that every node be patched before the funds would be safely returned.
Market participants are now watching to see if the patch is deployed across all nodes and whether the 4,000 BTC will be restored to the federation wallet, allowing the sidechain to resume normal operations.