- Liquid Network — a Bitcoin sidechain operated by Blockstream and a federation of 80+ exchanges and asset managers — confirmed ~4,000 BTC (~$320 million, ~95% of reserves) were stolen, with all new transactions halted as federation members work to restore normal activity.
- The perpetrators are described as “purported white-hat hackers” who exploit vulnerabilities and typically return funds for a fee; preliminary evidence from cybersecurity firm FailSafe points to a bug allowing unauthorized minting of L-BTC (Liquid Bitcoin).
- Liquid is widely used by exchanges including BTSE and Bitfinex (same parent as Tether) for fast, low-cost Bitcoin settlement — a $320M breach that halts the network creates immediate operational disruption for participants and raises questions about the federation model’s security assumptions.
- The breach follows a $6M exploit of a Crypto.com-linked lending platform last week and the August Coldcard cold wallet hack — representing an accelerating pattern of attacks on crypto infrastructure across custody, lending, and settlement layers in 2026.
What Happened?
Liquid Network confirmed Sunday that ~4,000 Bitcoin (~$320 million) were withdrawn from its Liquid Federation wallet by purported white-hat hackers who exploited a vulnerability via SideSwap, a settlement platform authorized to handle transfers. Liquid said the signing key was not compromised. All new transactions on the network are halted while Blockstream and federation members attempt to contact the hackers on-chain with a signed message and restore operations. The network is managed by 80+ exchanges, infrastructure firms, and asset managers.
Why It Matters?
Liquid Network exists specifically to solve Bitcoin’s core scaling problem — slow, expensive on-chain transactions — by issuing L-BTC backed 1:1 by locked Bitcoin. A breach that drains 95% of reserves and halts transactions exposes a critical flaw in the federation’s validation and backing model, according to FailSafe CEO Aneirin Flynn. For major Liquid users like Bitfinex (which shares a parent with Tether, the world’s largest stablecoin issuer), operational disruption and counterparty risk concerns are immediate. The “white-hat” framing — which implies eventual fund return for a bounty — does not reduce the severity of the breach or the systemic questions it raises.
What’s Next?
The critical variable is whether the hackers return the funds and on what terms. White-hat exploits in crypto have resulted in full, partial, and zero recoveries — outcomes that vary widely by protocol and negotiation. If funds are returned, Liquid faces a credibility and architecture review; if not, $320M in exchange reserves are effectively lost. Either way, the incident accelerates regulatory and industry pressure for stronger custody and validation standards across Bitcoin’s layer-2 ecosystem.
Source: Bloomberg











