Add Decrypt as your preferred source to see more of our stories on Google.
In brief
Liquid disabled its bridge nodes on Sunday after about 4,000 BTC left the federation wallet that backs L-BTC.
The withdrawal used SideSwap's peg-out key, which Liquid says was not compromised, pointing instead to a bug in Elements.
The wallet now holds roughly 200 BTC, around 5% of what it held before.
Blockstream's Liquid sidechain has been paused since Sunday, after about 4,000 BTC worth roughly $320 million left the federation wallet that backs every L-BTC in circulation.
SideSwap, a federation member running a peg-out service, said a customer sent it 4,000 L-BTC at 14:05 UTC. It burned them under a valid authorization, and 23 minutes later the federation paid out 3,996 BTC.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
Liquid said the funds moved through SideSwap's Peg-out Authorization Key, but that neither that key nor any other federation key was compromised. SideSwap said none of its systems were breached either, and pointed to a bug in Elements, the software Liquid runs on.
Blockstream has not explained the bug, though a fix for it was added to Liquid's underlying software five weeks earlier. Nothing was forced out of the wallet: someone created L-BTC that no Bitcoin was backing, then cashed it in through a peg-out that looked ordinary.
The wallet held around 4,200 BTC before Sunday and roughly 200 after.
The party left an on-chain message reading "we are whitehats. contact us on chain." Blockstream answered an hour later with an email address, and the two have traded PGP-signed messages inside Bitcoin transactions since.
The hackers offered to send most of the coins back, then attached a condition: patch the bug first, because the chain is still at risk at the latest commit, and update every node. Blockstream's reply, "Yes, thank you," answered the earlier offer, and was confirmed in the same block as the condition.
Ledger chief technology officer Charles Guillemet initially argued that "White hats don't drain a bridge and then solicit an "on-chain" contact," likening it to the Ronin and Euler hacks. He briefly allowed they might be people who "intensively played with recent LLMs," then hardened once the condition appeared: white hat practice has "changed," he wrote, adding that, "Now they steal the money and refuse to give back the funds before the vulnerability is fixed..."
Former Blockstream security chief Samson Mow, who published a timeline of the exchange, puts the hackers' address at about 3,998.5 BTC.
Other assets on Liquid, including USDT, DePix and tokenized real-world assets, were untouched, and Bitcoin's own network is unaffected.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.