Liquid Network's Bitcoin bridge was drained of roughly 4,000 BTC — about $320 million — in an incident the attacker claims was a white-hat operation. The funds were consolidated into a single address that still holds nearly all of them, and Liquid has frozen the bridge while it investigates.
The white hat claim
The attacker left an on-chain message identifying themselves as white hats and asked Liquid to contact them on-chain. Later, the same address signed another message asking whether sending most of the funds back to the federation wallet would be acceptable. Ledger CTO Charles Guillemet questioned the white hat label, comparing the incident to the Ronin hack and noting that white hats don't drain a bridge and then solicit on-chain contact.
Liquid's response
Liquid froze its bridge and disabled bridge nodes, preventing new transactions from entering the chain. Exchanges were notified and have paused or are preparing to pause L-BTC deposits and withdrawals. Other Liquid assets, including USDT, DePix, and real-world assets, remain unaffected.
The technical question
Liquid said the transfer used the SideSwap Peg-out Authorization Key, which it insists was not compromised. Blockstream traced the LBTC to a bug in the Elements software. That's a key detail: the bug is in the underlying software, not necessarily the key.
What's left
The stolen funds represented about 95% of all Bitcoin pegged to Liquid, according to Galaxy Research. The federation wallet retains roughly 197 BTC after the incident. The address holding the stolen funds, bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, still holds about 3,998 BTC as of press time.
The attacker's latest message asked whether sending most of the funds back to the federation wallet would be acceptable. So far, there's no public response from Liquid. Exchanges that paused L-BTC trading are waiting on the investigation before resuming.




