Liquid Network Hackers Return Most of $320M Bitcoin Haul

Liquid Network hackers returned 3,400 BTC after draining $320 million from its federation wallet, but about $47 million in Bitcoin remains outstanding.

Sep 8, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Liquid Network just watched roughly $320 million in Bitcoin walk out of the wallet backing its network, and those behind the drain say they did it to help.

About 4,000 bitcoin was withdrawn from Liquid’s federation wallet on Sept. 6, draining nearly all of its approximately 4,200 BTC reserve and prompting operators to pause the network, Reuters reported.

The incident was not a conventional private-key theft. Liquid said the unauthorized withdrawal used its Peg-out Authorization Key (PAK) even though the key itself was not compromised, but the precise vulnerability has not yet been publicly explained.

The people behind the withdrawal identified themselves as white hat hackers and said they would return most of the funds after the vulnerability was fixed. A report from Binance says that 3,400 of the stolen crypto has since been returned, leaving 600 still out.

How the unauthorized Liquid withdrawal happened

To understand how the Bitcoin got out, it helps first to understand what Liquid and SideSwap do. 

Liquid is a federated Bitcoin sidechain where users can lock bitcoin and receive L-BTC, which is intended to be backed one-for-one by bitcoin held in the federation wallet. Converting L-BTC back into bitcoin through the network is known as a peg-out.

SideSwap provides wallet and swap services for Liquid users, but it does not operate the underlying federation or peg-out mechanism.

According to an X post from Liquid, the attackers initiated an unauthorized transfer of funds using the Peg-out Authorization Key (PAK) without compromising the key itself.

That makes the incident unusual because the keys were meant to unlock the funds only when the parameters were right, but in this hack, they still allowed the funds to move.

Liquid’s operators are investigating the incident, and many technical details remain unknown. Other assets issued on Liquid, including Tether, were reportedly unaffected. The network remains paused while Blockstream and federation members strengthen security, resolve a resulting chain split and prepare for a safe restart.

Advertisement

The people behind the attack have not been identified. They called themselves “white hats” over encrypted communications.

There is still a question over that white hat claim. Security researchers who operate as white hats normally have permission to test a system and report what they find, while these attackers exploited a live system and moved its Bitcoin without permission. Whether their stated motive was genuine remains unknown, even after returning most of the withdrawn funds.

The bigger risk is what users cannot see

For users, the incident reminds them that keeping crypto secure is about more than protecting a private key. A system can have its authorization keys intact and still suffer a serious loss if a flaw causes those controls to approve something they were never supposed to.

That matters because crypto users increasingly rely on exchanges, sidechains, bridges, and other services to move assets between networks. When those systems fail, users can lose access to their funds or face frozen withdrawals even when their own wallets and credentials were never compromised.

The lesson extends beyond cryptocurrency: Protecting authorization keys is not enough if a flaw elsewhere in the transaction process can cause valid controls to approve an illegitimate request. Enterprises should test complete authorization workflows, monitor for anomalous transactions, impose limits on unusually large transfers and maintain emergency controls that can quickly suspend affected systems.

For now, users should not send bitcoin to Liquid peg-in addresses until the network confirms it has safely restarted. They should also watch for Liquid’s technical explanation, confirmation that L-BTC is fully backed again and updates on the approximately 598 BTC still outstanding.

Read more: Crypto users face risks beyond flaws in blockchain infrastructure, as malicious browser extensions can impersonate trusted wallets and steal seed phrases or private keys.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.