Binance Square
#liquidnetwork

liquidnetwork

13,505 views
89 Discussing
Sienna Leo-你真棒-带我走
·
--
#LiquidNetworkSuffers$320MExploit 🚨🔐 Liquid Network Suffers $320M Exploit 🔐🚨   The unsettling part is not simply that $320 million moved. It is that the transaction reportedly passed through an authorized route while the underlying security failure was elsewhere.   Around 4,000 BTC was withdrawn from Liquid’s federation wallet, roughly 95% of its reported reserves. The network paused activity as the incident unfolded.   And here is the detail worth remembering: the federation and SideSwap keys were reportedly not compromised. Investigators instead linked the incident to a flaw in Elements, the software powering Liquid.   The story became even stranger when the attackers claimed to be white hats. After the network was patched, about 3,400 BTC was reportedly returned, while roughly 598.5 BTC remained with the attacker.   That changes how I look at security: a valid signature does not automatically mean a safe transaction. Infrastructure must validate what is being authorized, not merely who signed it.   The memorable lesson: in crypto, security is only as strong as the assumptions beneath the transaction. Which matters more to you, secure keys or secure code?   Disclaimer: This post is for educational purposes only and is not financial advice.   #LiquidNetwork #Bitcoin #GrowWithSAC $TIA $SENT $MINA
#LiquidNetworkSuffers$320MExploit
🚨🔐 Liquid Network Suffers $320M Exploit 🔐🚨

The unsettling part is not simply that $320 million moved. It is that the transaction reportedly passed through an authorized route while the underlying security failure was elsewhere.

Around 4,000 BTC was withdrawn from Liquid’s federation wallet, roughly 95% of its reported reserves. The network paused activity as the incident unfolded.

And here is the detail worth remembering: the federation and SideSwap keys were reportedly not compromised. Investigators instead linked the incident to a flaw in Elements, the software powering Liquid.

The story became even stranger when the attackers claimed to be white hats. After the network was patched, about 3,400 BTC was reportedly returned, while roughly 598.5 BTC remained with the attacker.

That changes how I look at security: a valid signature does not automatically mean a safe transaction. Infrastructure must validate what is being authorized, not merely who signed it.

The memorable lesson: in crypto, security is only as strong as the assumptions beneath the transaction. Which matters more to you, secure keys or secure code?

Disclaimer: This post is for educational purposes only and is not financial advice.

#LiquidNetwork #Bitcoin #GrowWithSAC $TIA $SENT $MINA
·
--
#sideswapsuspendsliquidservices 🚨 A software glitch just created a serious problem for Liquid users. ⚠️ A customer reportedly minted around 4,000 fake L-BTC through an exploit and then withdrew roughly 3,996 real BTC from the Liquid Federation. The incident was processed through SideSwap before Blockstream flagged the exploit. SideSwap has since suspended swaps, peg-ins and peg-outs while the network recovers. For traders, the most important thing right now is simple: ⚠️ Avoid new peg-in or peg-out transactions until services are restored. SideSwap is non-custodial, meaning users generally retain control of assets held in their own wallets, but that doesn't eliminate risks related to affected protocols or pending transactions. No need to panic — but definitely don’t take unnecessary risks while the situation is being investigated. When a protocol is under attack, protecting capital comes first. Not financial advice. $BTC {spot}(BTCUSDT) $ETH {spot}(ETHUSDT) $BNB {spot}(BNBUSDT) #liquidnetwork #DeFiExploit #CryptoSecurity #Bitcoin #crypt
#sideswapsuspendsliquidservices
🚨 A software glitch just created a serious problem for Liquid users. ⚠️

A customer reportedly minted around 4,000 fake L-BTC through an exploit and then withdrew roughly 3,996 real BTC from the Liquid Federation.

The incident was processed through SideSwap before Blockstream flagged the exploit. SideSwap has since suspended swaps, peg-ins and peg-outs while the network recovers.

For traders, the most important thing right now is simple:
⚠️ Avoid new peg-in or peg-out transactions until services are restored.

SideSwap is non-custodial, meaning users generally retain control of assets held in their own wallets, but that doesn't eliminate risks related to affected protocols or pending transactions.

No need to panic — but definitely don’t take unnecessary risks while the situation is being investigated.

When a protocol is under attack, protecting capital comes first.
Not financial advice.

$BTC
$ETH
$BNB
#liquidnetwork #DeFiExploit #CryptoSecurity #Bitcoin #crypt
$320M $BTC Drain: The Real Risk Wasn’t the Keys Nearly 4,000 BTC left Liquid’s reserves, while the signing keys reportedly remained uncompromised. The deeper issue appears to be a validation failure: unbacked L-BTC reportedly passed the peg-out process and triggered the release of real $BTC . That reveals a critical distinction: Valid authorization ≠ valid collateral. For bridges and wrapped assets, signatures alone aren’t enough. The system must verify: Origin → Validity → Backing → Redemption The real question now: Can Liquid prevent unbacked assets from becoming valid claims on real BTC again? That’s the bigger lesson from this incident — and one worth watching across crypto infrastructure. #Bitcoin #Crypto #LiquidNetwork
$320M $BTC Drain: The Real Risk Wasn’t the Keys
Nearly 4,000 BTC left Liquid’s reserves, while the signing keys reportedly remained uncompromised.
The deeper issue appears to be a validation failure: unbacked L-BTC reportedly passed the peg-out process and triggered the release of real $BTC .
That reveals a critical distinction:
Valid authorization ≠ valid collateral.
For bridges and wrapped assets, signatures alone aren’t enough. The system must verify:
Origin → Validity → Backing → Redemption
The real question now:
Can Liquid prevent unbacked assets from becoming valid claims on real BTC again?
That’s the bigger lesson from this incident — and one worth watching across crypto infrastructure.
#Bitcoin #Crypto #LiquidNetwork
·
--
$BTC Liquid Network has reportedly paused operations after a purported $320 million “white-hat” Bitcoin withdrawal. That pause is the key development. Whatever the intent behind the withdrawal, halting the network signals that the issue is serious enough to require immediate containment and review. For users, the focus should stay on facts—not labels. “White hat” claims do not remove the need for full transparency around how the funds were accessed, what vulnerability was involved, who is coordinating the response, and how affected will be protected. $BTC This is also a reminder that sidechain infrastructure carries its own operational and security risks, even when the underlying asset is Bitcoin. Next, the community needs a detailed incident report, a remediation timeline, and clear confirmation of the status of the withdrawn . Will Liquid Network provide that level of transparency before services fully resume? #Bitcoin #CryptoSecurity #LiquidNetwork
$BTC

Liquid Network has reportedly paused operations after a purported $320 million “white-hat” Bitcoin withdrawal.

That pause is the key development. Whatever the intent behind the withdrawal, halting the network signals that the issue is serious enough to require immediate containment and review.

For users, the focus should stay on facts—not labels. “White hat” claims do not remove the need for full transparency around how the funds were accessed, what vulnerability was involved, who is coordinating the response, and how affected will be protected.

$BTC

This is also a reminder that sidechain infrastructure carries its own operational and security risks, even when the underlying asset is Bitcoin.

Next, the community needs a detailed incident report, a remediation timeline, and clear confirmation of the status of the withdrawn .

Will Liquid Network provide that level of transparency before services fully resume?

#Bitcoin #CryptoSecurity #LiquidNetwork
·
--
$BTC A reported 4,000 has been drained from Liquid Network — and the attackers are calling themselves “white hats.” The group claims it will return “most” of the funds once the underlying vulnerability is fixed. That wording is doing a lot of work. $BTC This is a serious security moment for the Bitcoin sidechain ecosystem. Even when attackers frame an exploit as a rescue operation, users are left facing the same immediate questions: where did the failure occur, who controls the funds now, and what safeguards were missing? The next update that matters is not the promise of a return. It’s a transparent technical explanation of the vulnerability, a confirmed remediation plan, and clarity on how affected will be handled. Would you trust funds back in the system after an incident like this, even if the exploit is patched? #Bitcoin #CryptoSecurity #LiquidNetwork
$BTC

A reported 4,000 has been drained from Liquid Network — and the attackers are calling themselves “white hats.”

The group claims it will return “most” of the funds once the underlying vulnerability is fixed. That wording is doing a lot of work.

$BTC

This is a serious security moment for the Bitcoin sidechain ecosystem. Even when attackers frame an exploit as a rescue operation, users are left facing the same immediate questions: where did the failure occur, who controls the funds now, and what safeguards were missing?

The next update that matters is not the promise of a return. It’s a transparent technical explanation of the vulnerability, a confirmed remediation plan, and clarity on how affected will be handled.

Would you trust funds back in the system after an incident like this, even if the exploit is patched?

#Bitcoin #CryptoSecurity #LiquidNetwork
🚨 Massive $320 Million Bitcoin Exploit: Are 'White-Hat' Hackers Negotiating with Blockstream? A staggering $320M worth of Bitcoin ($BTC) has been suddenly withdrawn from the Liquid network in a major potential security breach. Blockstream and the mysterious hackers are currently communicating via PGP-signed messages embedded directly within on-chain Bitcoin transactions. 🔹 $320M in $BTC moved out of Liquid network in an unexpected transfer. 🔹 Attackers claim white-hat status while negotiating with Blockstream developers. 🔹 On-chain communications are being actively conducted using PGP signatures. 🔹 Market analysts and security firms are closely watching the resolution. This situation highlights the ongoing critical importance of cross-chain infrastructure security. Keep a close watch on on-chain movements! $BTC #Bitcoin #CryptoSecurity #LiquidNetwork #Write2Earn
🚨 Massive $320 Million Bitcoin Exploit: Are 'White-Hat' Hackers Negotiating with Blockstream?

A staggering $320M worth of Bitcoin ($BTC ) has been suddenly withdrawn from the Liquid network in a major potential security breach. Blockstream and the mysterious hackers are currently communicating via PGP-signed messages embedded directly within on-chain Bitcoin transactions.

🔹 $320M in $BTC moved out of Liquid network in an unexpected transfer.
🔹 Attackers claim white-hat status while negotiating with Blockstream developers.
🔹 On-chain communications are being actively conducted using PGP signatures.
🔹 Market analysts and security firms are closely watching the resolution.

This situation highlights the ongoing critical importance of cross-chain infrastructure security. Keep a close watch on on-chain movements!

$BTC #Bitcoin #CryptoSecurity #LiquidNetwork #Write2Earn
🔴₿💰 $320M Bitcoin Withdrawal Hits Liquid Network 🚨🔗 The Bitcoin-based Liquid Network reported that around 4,000 BTC, worth approximately $320 million, were withdrawn from its federation wallet. 💸 🚨 The network paused operations after detecting the incident. 🏦 Exchanges were asked to suspend LBTC deposits and withdrawals. 🕵️ The attackers claimed to be “white hats,” but this has not been confirmed. 🛡️ Importantly, Bitcoin’s main network was not compromised. ₿🔐 🌐⚠️ Why It Matters for Crypto The incident highlights the importance of security and custody controls in crypto infrastructure, while Bitcoin itself continued operating normally. 🔒₿📊 #Bitcoin ₿ #LiquidNetwork 🔴 #CryptoSecurity 🔐 #CryptoHack 🚨 #Cybersecurity 🛡️
🔴₿💰 $320M Bitcoin Withdrawal Hits Liquid Network 🚨🔗
The Bitcoin-based Liquid Network reported that around 4,000 BTC, worth approximately $320 million, were withdrawn from its federation wallet. 💸
🚨 The network paused operations after detecting the incident.
🏦 Exchanges were asked to suspend LBTC deposits and withdrawals.
🕵️ The attackers claimed to be “white hats,” but this has not been confirmed.
🛡️ Importantly, Bitcoin’s main network was not compromised. ₿🔐
🌐⚠️ Why It Matters for Crypto
The incident highlights the importance of security and custody controls in crypto infrastructure, while Bitcoin itself continued operating normally. 🔒₿📊
#Bitcoin #LiquidNetwork 🔴 #CryptoSecurity 🔐 #CryptoHack 🚨 #Cybersecurity 🛡️
🚨 BREAKING: SIDESWAP SUSPENDS LIQUID SERVICE SideSwap has reportedly suspended its service on the Liquid Network, adding further uncertainty around activity on the Bitcoin sidechain. 🔹 SideSwap: Service suspended 🔹 Network: Liquid 🔹 Impact: Users may face disruptions to swaps and related services 🔹 Market focus: Liquidity, security and recovery updates The suspension comes as the crypto community closely watches developments surrounding the Liquid ecosystem. ⚠️ Traders should stay alert and wait for official updates before making decisions involving affected assets. What do you think — temporary disruption or a bigger warning for Liquid? 👇 #Bitcoin #liquidnetwork #SideSwap #CryptoNews🚀🔥 #BinanceSquare
🚨 BREAKING: SIDESWAP SUSPENDS LIQUID SERVICE

SideSwap has reportedly suspended its service on the Liquid Network, adding further uncertainty around activity on the Bitcoin sidechain.

🔹 SideSwap: Service suspended
🔹 Network: Liquid
🔹 Impact: Users may face disruptions to swaps and related services
🔹 Market focus: Liquidity, security and recovery updates

The suspension comes as the crypto community closely watches developments surrounding the Liquid ecosystem.

⚠️ Traders should stay alert and wait for official updates before making decisions involving affected assets.

What do you think — temporary disruption or a bigger warning for Liquid? 👇

#Bitcoin #liquidnetwork #SideSwap #CryptoNews🚀🔥 #BinanceSquare
Liquid Network has paused its sidechain activity after approximately 4,000 BTC, worth around $320M, was withdrawn from its federation wallet. What makes this incident interesting is that Liquid says the SideSwap PAK itself was not compromised, and no other keys were reported compromised. The network has not yet disclosed the root vulnerability behind the withdrawal. An onchain message from the parties involved reportedly said: we are whitehats. contact us on chain. Liquid has since disabled bridge nodes and notified exchanges to suspend LBTC deposits and withdrawals. Other assets on Liquid, including USDT, DePix and RWAs, were reported unaffected. The bigger question for me is simple: if the authorization key wasn’t compromised, what allowed such a large withdrawal to happen? #Bitcoin #LiquidNetwork #CryptoSecurity
Liquid Network has paused its sidechain activity after approximately 4,000 BTC, worth around $320M, was withdrawn from its federation wallet.

What makes this incident interesting is that Liquid says the SideSwap PAK itself was not compromised, and no other keys were reported compromised. The network has not yet disclosed the root vulnerability behind the withdrawal.

An onchain message from the parties involved reportedly said: we are whitehats. contact us on chain.

Liquid has since disabled bridge nodes and notified exchanges to suspend LBTC deposits and withdrawals. Other assets on Liquid, including USDT, DePix and RWAs, were reported unaffected.

The bigger question for me is simple: if the authorization key wasn’t compromised, what allowed such a large withdrawal to happen?

#Bitcoin #LiquidNetwork #CryptoSecurity
·
--
Bullish
#LiquidNetworkSuffers$320MExploit 🚨 A $320M Bitcoin security incident just put Liquid Network under serious pressure — but the story has taken an unusual turn. Around 4,000 BTC, worth roughly $320 million, was withdrawn from Liquid Network’s federation wallet after a security vulnerability was exploited. Liquid temporarily paused network activity while the issue was investigated. The withdrawal was processed through SideSwap’s peg-out system, although Liquid said the authorization key itself was not compromised. The party behind the withdrawal described itself as a white-hat hacker and indicated the funds could be returned after the vulnerability was fixed. That has now partly happened. After Blockstream said its bridge nodes had been patched, roughly 3,400 BTC — about 85% of the withdrawn amount — was returned, while nearly 600 BTC remained with the attacker at the latest reported update. Why does this matter? The incident highlights how security risks can emerge in the infrastructure connecting Bitcoin with sidechains and settlement systems — even without Bitcoin’s base network itself being compromised. The next thing to watch is whether the remaining BTC is returned and what the final technical investigation reveals about the vulnerability. Sometimes the biggest security incidents reveal more about infrastructure risk than price action does. 👀 #bitcoin #BTC #liquidnetwork #CryptoSecurityAlert $SOPH $UAI $BR {future}(BRUSDT) {future}(UAIUSDT) {future}(SOPHUSDT)
#LiquidNetworkSuffers$320MExploit
🚨 A $320M Bitcoin security incident just put Liquid Network under serious pressure — but the story has taken an unusual turn.

Around 4,000 BTC, worth roughly $320 million, was withdrawn from Liquid Network’s federation wallet after a security vulnerability was exploited.

Liquid temporarily paused network activity while the issue was investigated. The withdrawal was processed through SideSwap’s peg-out system, although Liquid said the authorization key itself was not compromised.

The party behind the withdrawal described itself as a white-hat hacker and indicated the funds could be returned after the vulnerability was fixed.

That has now partly happened.

After Blockstream said its bridge nodes had been patched, roughly 3,400 BTC — about 85% of the withdrawn amount — was returned, while nearly 600 BTC remained with the attacker at the latest reported update.

Why does this matter?

The incident highlights how security risks can emerge in the infrastructure connecting Bitcoin with sidechains and settlement systems — even without Bitcoin’s base network itself being compromised.

The next thing to watch is whether the remaining BTC is returned and what the final technical investigation reveals about the vulnerability.

Sometimes the biggest security incidents reveal more about infrastructure risk than price action does. 👀

#bitcoin #BTC #liquidnetwork #CryptoSecurityAlert
$SOPH $UAI $BR

#LiquidNetworkSuffers$320MExploit 🚨🌊 LIQUID NETWORK SUFFERS $320M EXPLOIT: THE BITCOIN SECURITY WAKE-UP CALL 🌊🚨   When trust sits behind a wall of code, One hidden flaw can make billions feel exposed.   Liquid Network has suffered a major security incident, with approximately 4,000 BTC worth around $320 million withdrawn from its federation wallet. The network subsequently halted new transactions.   The most unsettling detail? Liquid reported that the cryptographic keys used in the withdrawal were not compromised. The funds moved through SideSwap, an authorized settlement route.   That shifts the conversation from a simple “stolen keys” story toward a deeper infrastructure question: can validation logic and settlement mechanisms remain trustworthy under adversarial conditions?   The individuals behind the withdrawal have described themselves as white-hat hackers and reportedly offered to return most of the Bitcoin after the underlying vulnerability is fixed. That claim and the recovery outcome remain developments to watch.   For crypto markets, the bigger concern is not simply the headline loss. Incidents involving settlement infrastructure can challenge confidence in bridges, federated custody, wrapped assets, and the systems connecting Bitcoin liquidity to trading platforms.   The lesson is uncomfortable but important: security is not proven when nothing goes wrong; it is proven when the system survives what should never have been possible.   Do you think the potential return of the funds changes how seriously the market should view this exploit?   Disclaimer: This is informational content, not financial advice. The incident remains developing, and technical details may change as investigations continue.   #LiquidNetwork #BitcoinSecurity #GrowWithSAC $FET $ATOM $BARD
#LiquidNetworkSuffers$320MExploit
🚨🌊 LIQUID NETWORK SUFFERS $320M EXPLOIT: THE BITCOIN SECURITY WAKE-UP CALL 🌊🚨

When trust sits behind a wall of code,
One hidden flaw can make billions feel exposed.

Liquid Network has suffered a major security incident, with approximately 4,000 BTC worth around $320 million withdrawn from its federation wallet. The network subsequently halted new transactions.

The most unsettling detail? Liquid reported that the cryptographic keys used in the withdrawal were not compromised. The funds moved through SideSwap, an authorized settlement route.

That shifts the conversation from a simple “stolen keys” story toward a deeper infrastructure question: can validation logic and settlement mechanisms remain trustworthy under adversarial conditions?

The individuals behind the withdrawal have described themselves as white-hat hackers and reportedly offered to return most of the Bitcoin after the underlying vulnerability is fixed. That claim and the recovery outcome remain developments to watch.

For crypto markets, the bigger concern is not simply the headline loss. Incidents involving settlement infrastructure can challenge confidence in bridges, federated custody, wrapped assets, and the systems connecting Bitcoin liquidity to trading platforms.

The lesson is uncomfortable but important: security is not proven when nothing goes wrong; it is proven when the system survives what should never have been possible.

Do you think the potential return of the funds changes how seriously the market should view this exploit?

Disclaimer: This is informational content, not financial advice. The incident remains developing, and technical details may change as investigations continue.

#LiquidNetwork #BitcoinSecurity #GrowWithSAC $FET $ATOM $BARD
$320M Liquid Incident: The Market May Be Missing the Real Risk Around 4,000 BTC worth roughly $320M was withdrawn from Liquid Network's federation wallet, forcing the network to halt new transactions. The headline is another crypto hack. The deeper issue is infrastructure concentration. When a system controlling billions relies on a limited federation structure, one software or authorization failure can create disproportionate systemic consequences. Liquid said the cryptographic key itself was not compromised, while investigators pointed toward an Elements software vulnerability. This creates an important market question: Are investors correctly pricing infrastructure risk beneath the Bitcoin ecosystem? The lesson isn't “Bitcoin is unsafe.” It's that the security of the layers built around Bitcoin deserves much more attention. $SOLV $IOST $CATI #Bitcoin #CryptoSecurity #LiquidNetwork #LiquidNetworkSuffers$320MExploit #ZeroResearch
$320M Liquid Incident: The Market May Be Missing the Real Risk

Around 4,000 BTC worth roughly $320M was withdrawn from Liquid Network's federation wallet, forcing the network to halt new transactions.

The headline is another crypto hack.

The deeper issue is infrastructure concentration.

When a system controlling billions relies on a limited federation structure, one software or authorization failure can create disproportionate systemic consequences.

Liquid said the cryptographic key itself was not compromised, while investigators pointed toward an Elements software vulnerability.

This creates an important market question:

Are investors correctly pricing infrastructure risk beneath the Bitcoin ecosystem?

The lesson isn't “Bitcoin is unsafe.”

It's that the security of the layers built around Bitcoin deserves much more attention.

$SOLV $IOST $CATI

#Bitcoin #CryptoSecurity #LiquidNetwork #LiquidNetworkSuffers$320MExploit #ZeroResearch
Article
The $320M Liquid Hack: How a Software Bug Let 4,000 BTC Walk OutNearly 4,000 BTC worth roughly $320 million was drained from Bitcoin sidechain Liquid. But this wasn't a simple private-key hack — and the people holding the Bitcoin now say they want to give most of it back. On September 6, the Liquid Network suffered one of the largest crypto security incidents of 2026. Approximately 4,000 BTC was withdrawn from the Liquid Federation's Bitcoin reserve wallet, worth around $320 million at the time. Liquid subsequently paused bridge activity, while exchanges suspended or prepared to suspend L-BTC deposits and withdrawals. Then the story took an unexpected turn. The attackers identified themselves on-chain as "whitehats" and told Blockstream they would return most of the Bitcoin — but only after the underlying vulnerability was fixed and the network's nodes were patched. At the time of writing, the roughly 4,000 BTC remained under the attackers' control. So what actually happened? This Wasn't a Bitcoin Hack The first important distinction: Bitcoin itself was not hacked. The incident happened on Liquid, a Bitcoin sidechain operated through the Liquid Federation. Liquid's model is built around a two-way peg. Users move BTC into the federation's Bitcoin reserve and receive an equivalent amount of Liquid Bitcoin, or LBTC, on the sidechain. In normal operation: BTC → Liquid Federation → LBTC And when users want to leave Liquid: LBTC → burned → BTC released Liquid's own documentation describes LBTC as being backed 1:1 by Bitcoin held in the Federation's multisignature wallet. The security model is deliberately designed so that the federation doesn't depend on a single private key. The Federation uses an 11-of-15 multisig structure, with keys held by separate functionaries. Peg-outs also use a Peg-out Authorization Key, or PAK, to restrict where Bitcoin can be sent. And yet, approximately 4,000 BTC left the reserve. That is what makes this incident so interesting. The Keys Apparently Weren't Stolen According to Liquid and reporting from SideSwap, the incident did not involve the theft of the federation's signing credentials. Instead, the transaction went through the normal peg-out mechanism. The problem appears to have been somewhere deeper in the software stack. SideSwap said the L-BTC involved in the transaction was created through a bug in Elements, the open-source blockchain software underlying Liquid. In other words, the attacker appears to have exploited a flaw that allowed roughly 4,000 LBTC to exist even though the corresponding Bitcoin had never been deposited into the federation. Those tokens were then presented for redemption. The federation's infrastructure effectively processed the request as a valid peg-out and released real Bitcoin. The result was an extraordinary conversion: Fake/illegitimate LBTC → legitimate peg-out → real BTC The attackers ended up with approximately 3,996 BTC in a Bitcoin address after the transaction. The $320 Million Problem This exposes a fundamental risk in any bridged or wrapped asset system. The security of the bridge is not determined only by how well the underlying Bitcoin is protected. It also depends on whether the system can correctly answer a much simpler question: "Does this token actually exist legitimately?" Liquid's entire peg relies on a 1:1 relationship between LBTC circulating on the sidechain and BTC held by the federation. If software allows an attacker to manufacture LBTC outside that accounting model, the attacker may be able to redeem those artificial tokens for real Bitcoin. The vault can remain secure. The private keys can remain secure. The multisig can remain intact. And the system can still lose hundreds of millions of dollars. That is the critical lesson from this incident. Why Didn't the 11-of-15 Multisig Stop It? At first glance, this seems like exactly the kind of attack that an 11-of-15 multisig should prevent. But multisig protects against unauthorized spending. It does not automatically protect against a transaction that the system itself considers valid. Liquid's documented peg-out process requires the federation's functionaries to verify the peg-out request and then sign the corresponding Bitcoin transaction. If the underlying software incorrectly determines that an LBTC redemption is legitimate, the multisig participants can end up doing precisely what they were designed to do: sign a valid transaction. That distinction is crucial. This wasn't necessarily: "The attacker stole 11 private keys." It was closer to: "The attacker found a way to make the system believe the withdrawal was legitimate." That's a fundamentally different class of vulnerability. Then the Hackers Did Something Strange After moving the Bitcoin, the attackers didn't immediately disappear. Instead, they left an on-chain message identifying themselves as "whitehats" and asking Blockstream to contact them. Blockstream subsequently responded through Bitcoin transactions and encrypted communication. The attackers then reportedly offered to return most of the Bitcoin — with one major condition: Fix the bug first. They wanted confirmation that the vulnerability had been patched across the relevant nodes before returning the funds. Blockstream later sent a signed on-chain message indicating that the bridge nodes had been patched and that the funds could be returned. But the Bitcoin had not yet moved at the time of reporting. So the biggest crypto theft story of the day has, unusually, turned into a negotiation between the protocol developers and the people who exploited it. Liquid Paused the Bridge Following the incident, Liquid disabled bridge nodes and exchanges moved to suspend L-BTC deposits and withdrawals. That makes sense: if the underlying accounting vulnerability isn't fixed, simply returning the stolen BTC doesn't solve the problem. The network needs to establish that the same exploit cannot be repeated. Liquid can continue to exist as a blockchain, but the bridge between Liquid and Bitcoin is the critical point being protected. This distinction matters because Liquid is not Bitcoin. Blockstream's own documentation describes Liquid as a Bitcoin sidechain that operates independently from Bitcoin's base layer. Bitcoin does not depend on Liquid to function. So there is no indication that Bitcoin's consensus mechanism or Bitcoin's underlying proof-of-work was compromised. The failure occurred at the sidechain and peg layer. The Bigger Lesson for Crypto This incident is bigger than Liquid. It is another reminder that crypto infrastructure has multiple layers of security — and protecting one layer doesn't automatically protect the others. You can have: Hardware-secured private keysMultisignature walletsGeographically distributed validatorsWhitelisted withdrawal addressesTimelocks and emergency recovery procedures …and still have a catastrophic failure if the software validating the assets contains a consensus bug. Liquid's architecture actually includes multiple additional safeguards. Its documentation describes an emergency recovery mechanism and timelocks designed to protect federation funds during prolonged network failure. But those protections are primarily designed around different failure scenarios. The lesson is not that multisig doesn't work. The lesson is that multisig cannot compensate for broken validation logic. The Most Interesting Part May Be What Happens Next The Bitcoin is still the central piece of the puzzle. If the attackers genuinely return most of the ~4,000 BTC after the patch, the incident could become an unusual example of a massive white-hat intervention: a vulnerability was exploited for real money, the funds were temporarily secured by the researchers, and the protocol was forced to fix the underlying weakness. But until the Bitcoin actually moves back, it remains a claim — not a completed recovery. And there are still major questions to answer: Exactly which Elements bug enabled the unauthorized LBTC creation? How did the attacker discover it? Why did the federation's validation process accept the resulting peg-out? Could the vulnerability have been exploited earlier? How many nodes and systems were affected? And perhaps most importantly: How much confidence should users place in a bridged asset whose security ultimately depends on software validating a 1:1 backing relationship? The Liquid incident is therefore not simply a story about $320 million being stolen. It is a case study in the difference between protecting keys and protecting the rules those keys are programmed to enforce. And in crypto, sometimes the second problem is the bigger one. #bitcoin #liquidnetwork #CryptoSecurity #BTC $BTC $BNB $ETH {spot}(ETHUSDT) {spot}(BNBUSDT) {spot}(BTCUSDT)

The $320M Liquid Hack: How a Software Bug Let 4,000 BTC Walk Out

Nearly 4,000 BTC worth roughly $320 million was drained from Bitcoin sidechain Liquid. But this wasn't a simple private-key hack — and the people holding the Bitcoin now say they want to give most of it back.
On September 6, the Liquid Network suffered one of the largest crypto security incidents of 2026.
Approximately 4,000 BTC was withdrawn from the Liquid Federation's Bitcoin reserve wallet, worth around $320 million at the time. Liquid subsequently paused bridge activity, while exchanges suspended or prepared to suspend L-BTC deposits and withdrawals.
Then the story took an unexpected turn.
The attackers identified themselves on-chain as "whitehats" and told Blockstream they would return most of the Bitcoin — but only after the underlying vulnerability was fixed and the network's nodes were patched.
At the time of writing, the roughly 4,000 BTC remained under the attackers' control.
So what actually happened?
This Wasn't a Bitcoin Hack
The first important distinction: Bitcoin itself was not hacked.
The incident happened on Liquid, a Bitcoin sidechain operated through the Liquid Federation.
Liquid's model is built around a two-way peg. Users move BTC into the federation's Bitcoin reserve and receive an equivalent amount of Liquid Bitcoin, or LBTC, on the sidechain.
In normal operation:
BTC → Liquid Federation → LBTC
And when users want to leave Liquid:
LBTC → burned → BTC released
Liquid's own documentation describes LBTC as being backed 1:1 by Bitcoin held in the Federation's multisignature wallet.
The security model is deliberately designed so that the federation doesn't depend on a single private key.
The Federation uses an 11-of-15 multisig structure, with keys held by separate functionaries. Peg-outs also use a Peg-out Authorization Key, or PAK, to restrict where Bitcoin can be sent.
And yet, approximately 4,000 BTC left the reserve.
That is what makes this incident so interesting.
The Keys Apparently Weren't Stolen
According to Liquid and reporting from SideSwap, the incident did not involve the theft of the federation's signing credentials.
Instead, the transaction went through the normal peg-out mechanism.
The problem appears to have been somewhere deeper in the software stack.
SideSwap said the L-BTC involved in the transaction was created through a bug in Elements, the open-source blockchain software underlying Liquid.
In other words, the attacker appears to have exploited a flaw that allowed roughly 4,000 LBTC to exist even though the corresponding Bitcoin had never been deposited into the federation.
Those tokens were then presented for redemption.
The federation's infrastructure effectively processed the request as a valid peg-out and released real Bitcoin.
The result was an extraordinary conversion:
Fake/illegitimate LBTC → legitimate peg-out → real BTC
The attackers ended up with approximately 3,996 BTC in a Bitcoin address after the transaction.
The $320 Million Problem
This exposes a fundamental risk in any bridged or wrapped asset system.
The security of the bridge is not determined only by how well the underlying Bitcoin is protected.
It also depends on whether the system can correctly answer a much simpler question:
"Does this token actually exist legitimately?"
Liquid's entire peg relies on a 1:1 relationship between LBTC circulating on the sidechain and BTC held by the federation.
If software allows an attacker to manufacture LBTC outside that accounting model, the attacker may be able to redeem those artificial tokens for real Bitcoin.
The vault can remain secure.
The private keys can remain secure.
The multisig can remain intact.
And the system can still lose hundreds of millions of dollars.
That is the critical lesson from this incident.
Why Didn't the 11-of-15 Multisig Stop It?
At first glance, this seems like exactly the kind of attack that an 11-of-15 multisig should prevent.
But multisig protects against unauthorized spending.
It does not automatically protect against a transaction that the system itself considers valid.
Liquid's documented peg-out process requires the federation's functionaries to verify the peg-out request and then sign the corresponding Bitcoin transaction.
If the underlying software incorrectly determines that an LBTC redemption is legitimate, the multisig participants can end up doing precisely what they were designed to do:
sign a valid transaction.
That distinction is crucial.
This wasn't necessarily:
"The attacker stole 11 private keys."
It was closer to:
"The attacker found a way to make the system believe the withdrawal was legitimate."
That's a fundamentally different class of vulnerability.
Then the Hackers Did Something Strange
After moving the Bitcoin, the attackers didn't immediately disappear.
Instead, they left an on-chain message identifying themselves as "whitehats" and asking Blockstream to contact them.
Blockstream subsequently responded through Bitcoin transactions and encrypted communication.
The attackers then reportedly offered to return most of the Bitcoin — with one major condition:
Fix the bug first.
They wanted confirmation that the vulnerability had been patched across the relevant nodes before returning the funds.
Blockstream later sent a signed on-chain message indicating that the bridge nodes had been patched and that the funds could be returned.
But the Bitcoin had not yet moved at the time of reporting.
So the biggest crypto theft story of the day has, unusually, turned into a negotiation between the protocol developers and the people who exploited it.
Liquid Paused the Bridge
Following the incident, Liquid disabled bridge nodes and exchanges moved to suspend L-BTC deposits and withdrawals.
That makes sense: if the underlying accounting vulnerability isn't fixed, simply returning the stolen BTC doesn't solve the problem.
The network needs to establish that the same exploit cannot be repeated.
Liquid can continue to exist as a blockchain, but the bridge between Liquid and Bitcoin is the critical point being protected.
This distinction matters because Liquid is not Bitcoin.
Blockstream's own documentation describes Liquid as a Bitcoin sidechain that operates independently from Bitcoin's base layer. Bitcoin does not depend on Liquid to function.
So there is no indication that Bitcoin's consensus mechanism or Bitcoin's underlying proof-of-work was compromised.
The failure occurred at the sidechain and peg layer.
The Bigger Lesson for Crypto
This incident is bigger than Liquid.
It is another reminder that crypto infrastructure has multiple layers of security — and protecting one layer doesn't automatically protect the others.
You can have:
Hardware-secured private keysMultisignature walletsGeographically distributed validatorsWhitelisted withdrawal addressesTimelocks and emergency recovery procedures
…and still have a catastrophic failure if the software validating the assets contains a consensus bug.
Liquid's architecture actually includes multiple additional safeguards. Its documentation describes an emergency recovery mechanism and timelocks designed to protect federation funds during prolonged network failure.
But those protections are primarily designed around different failure scenarios.
The lesson is not that multisig doesn't work.
The lesson is that multisig cannot compensate for broken validation logic.
The Most Interesting Part May Be What Happens Next
The Bitcoin is still the central piece of the puzzle.
If the attackers genuinely return most of the ~4,000 BTC after the patch, the incident could become an unusual example of a massive white-hat intervention: a vulnerability was exploited for real money, the funds were temporarily secured by the researchers, and the protocol was forced to fix the underlying weakness.
But until the Bitcoin actually moves back, it remains a claim — not a completed recovery.
And there are still major questions to answer:
Exactly which Elements bug enabled the unauthorized LBTC creation?
How did the attacker discover it?
Why did the federation's validation process accept the resulting peg-out?
Could the vulnerability have been exploited earlier?
How many nodes and systems were affected?
And perhaps most importantly:
How much confidence should users place in a bridged asset whose security ultimately depends on software validating a 1:1 backing relationship?
The Liquid incident is therefore not simply a story about $320 million being stolen.
It is a case study in the difference between protecting keys and protecting the rules those keys are programmed to enforce.
And in crypto, sometimes the second problem is the bigger one.
#bitcoin #liquidnetwork #CryptoSecurity #BTC
$BTC $BNB $ETH
·
--
Bearish
#LiquidNetworkSuffers$320MExploit 🚨 BREAKING: LIQUID NETWORK HIT BY A MASSIVE $320 MILLION EXPLOIT! 💥 ⚠️ A reported $320M exploit has sent shockwaves through the crypto market, raising fresh concerns about security and the risks surrounding cross-chain and wrapped-asset infrastructure. 💰 An attack of this scale can quickly trigger panic, liquidity concerns and increased selling pressure as traders reassess their exposure. 👀 The crypto community will now be watching closely for updates on the exploit, affected assets and any recovery efforts. 🔥 In crypto, one vulnerability can erase years of trust in minutes — security remains everything. #liquidnetwork #crypto #defi
#LiquidNetworkSuffers$320MExploit
🚨 BREAKING: LIQUID NETWORK HIT BY A MASSIVE $320 MILLION EXPLOIT! 💥
⚠️ A reported $320M exploit has sent shockwaves through the crypto market, raising fresh concerns about security and the risks surrounding cross-chain and wrapped-asset infrastructure.
💰 An attack of this scale can quickly trigger panic, liquidity concerns and increased selling pressure as traders reassess their exposure.
👀 The crypto community will now be watching closely for updates on the exploit, affected assets and any recovery efforts.
🔥 In crypto, one vulnerability can erase years of trust in minutes — security remains everything.
#liquidnetwork #crypto #defi
🚨 Alleged white-hat hackers drained ~$320M in BTC from Liquid Network, demanding a full bug fix across all nodes before returning funds. This highlights critical infrastructure risks in sidechain ecosystems—even trusted layers can face exploits. Market implication: Liquidity and trust in Liquid-linked BTC may face short-term pressure until patches are verified. Smart-money behavior isn’t confirmed—no evidence of institutional moves or profit claims. Will users regain confidence once the network is secured? #LiquidNetwork #BTCSecurity $BTC #TradingSignal #CryptoAnalysis
🚨 Alleged white-hat hackers drained ~$320M in BTC from Liquid Network, demanding a full bug fix across all nodes before returning funds.
This highlights critical infrastructure risks in sidechain ecosystems—even trusted layers can face exploits.
Market implication: Liquidity and trust in Liquid-linked BTC may face short-term pressure until patches are verified.
Smart-money behavior isn’t confirmed—no evidence of institutional moves or profit claims.
Will users regain confidence once the network is secured?
#LiquidNetwork #BTCSecurity

$BTC #TradingSignal #CryptoAnalysis
Nearly $320M in Bitcoin moved… and the network hit pause. This is the crypto story I wouldn't ignore. Liquid Network reported roughly 4,000 BTC, worth around $320M, withdrawn from its federation wallet. New transactions were halted as a precaution. That's roughly 95% of the 4,200 BTC reportedly held in that wallet. And here's the uncomfortable question: If the Bitcoin itself isn't broken, where exactly did the security model fail? The incident involved withdrawals through SideSwap, while Liquid said the cryptographic key itself wasn't compromised. Bullish interpretation: funds may eventually be recovered. Bearish interpretation: bridge/sidechain trust gets repriced. The lesson isn't “Bitcoin is unsafe.” It's custody architecture matters. Don't confuse Bitcoin's security with every layer built around it. #Bitcoin #LiquidNetwork #defi $BTC $SC $ETH #SideSwapSuspendsLiquidServices
Nearly $320M in Bitcoin moved… and the network hit pause.

This is the crypto story I wouldn't ignore.
Liquid Network reported roughly 4,000 BTC, worth around $320M, withdrawn from its federation wallet. New transactions were halted as a precaution.

That's roughly 95% of the 4,200 BTC reportedly held in that wallet.
And here's the uncomfortable question:
If the Bitcoin itself isn't broken, where exactly did the security model fail?
The incident involved withdrawals through SideSwap, while Liquid said the cryptographic key itself wasn't compromised.

Bullish interpretation: funds may eventually be recovered.
Bearish interpretation: bridge/sidechain trust gets repriced.
The lesson isn't “Bitcoin is unsafe.”
It's custody architecture matters.
Don't confuse Bitcoin's security with every layer built around it.

#Bitcoin #LiquidNetwork #defi
$BTC $SC $ETH

#SideSwapSuspendsLiquidServices
·
--
Bullish
🚨 Liquid Network Security Incident Liquid Network reports that ~4,000 BTC (~$320M) was withdrawn from its Federation wallet by purported white-hat hackers. The Liquid sidechain has been paused while the issue is investigated and resolved. Details are still developing worth watching closely. 👀 $BTC #bitcoin #liquidnetwork #Crypto {spot}(BTCUSDT)
🚨 Liquid Network Security Incident

Liquid Network reports that ~4,000 BTC (~$320M) was withdrawn from its Federation wallet by purported white-hat hackers.

The Liquid sidechain has been paused while the issue is investigated and resolved.

Details are still developing worth watching closely. 👀

$BTC #bitcoin #liquidnetwork #Crypto
🚨 WILD CRYPTO SECURITY ALERT Liquid Network has reportedly halted transactions after around 4,000 BTC roughly $320M was withdrawn from its federation wallet. Think about that for a second. 👀 This isn’t just a normal network pause. Liquid sits directly in the Bitcoin ecosystem, so an incident of this size naturally raises serious questions about security, transaction controls and infrastructure risk. What makes it even more interesting? The withdrawals reportedly involved SideSwap, while Liquid says the cryptographic key itself was not compromised. For now, the biggest signal isn’t panic —it’s what the investigation reveals next. 🔎 Watch the official updates closely. #Bitcoin #liquidnetwork #crypto $CATI {future}(CATIUSDT) $CFG {future}(CFGUSDT)
🚨 WILD CRYPTO SECURITY ALERT

Liquid Network has reportedly halted transactions after around 4,000 BTC

roughly $320M was withdrawn from its federation wallet.

Think about that for a second. 👀

This isn’t just a normal network pause. Liquid sits directly in the Bitcoin ecosystem, so an incident of this size naturally raises serious

questions about security, transaction controls and infrastructure risk.

What makes it even more interesting? The withdrawals reportedly involved SideSwap, while Liquid says the cryptographic key itself was not compromised.

For now, the biggest signal isn’t panic —it’s what the investigation reveals next. 🔎

Watch the official updates closely.

#Bitcoin #liquidnetwork #crypto
$CATI
$CFG
🚨 $320 MILLION JUST DISAPPEARED FROM A BITCOIN-BASED NETWORK Liquid Network reported that around 4,000 BTC were withdrawn from its federation wallet in a hack. That's roughly $320M worth of Bitcoin. The network says it has halted new transactions while the incident is investigated. Here's the scary part: The reported withdrawal happened even though Liquid said the cryptographic key itself was NOT compromised. Was this a security failure, an insider issue, or something else? 👇 What do YOU think happened? $BTC #Bitcoin #Crypto #LiquidNetwork {spot}(BTCUSDT)
🚨 $320 MILLION JUST DISAPPEARED FROM A BITCOIN-BASED NETWORK
Liquid Network reported that around 4,000 BTC were withdrawn from its federation wallet in a hack.
That's roughly $320M worth of Bitcoin.
The network says it has halted new transactions while the incident is investigated.
Here's the scary part:
The reported withdrawal happened even though Liquid said the cryptographic key itself was NOT compromised.
Was this a security failure, an insider issue, or something else?
👇 What do YOU think happened?
$BTC #Bitcoin #Crypto #LiquidNetwork
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number