A security breach occurred on the Liquid Network starting on September 6, 2026, when nearly 4,000 bitcoins—worth approximately $320 million or €275 million—were moved from the platform’s central reserves. This represented almost the entire stock of bitcoins held by the network. The attackers left a message in the main transaction for the management stating, "We are white hats. Contact us on-chain." However, Charles Guillemet, technical director of Ledger, questioned the "white hat" claim, explaining that legitimate security researchers usually report vulnerabilities before exploiting them, not after draining nearly all of the reserves. Until the bitcoins are returned to the network’s wallet, the "white hat" label remains a claim, not an established fact.
Liquid is a sidechain connected to the Bitcoin blockchain, designed to enable faster and more private transactions, as well as the creation of digital assets like stablecoins. To use Liquid, users deposit bitcoins through a process called "peg-in," which gives them L-BTC, a version of Bitcoin usable on the sidechain. To retrieve the original bitcoins, users perform a "peg-out," which destroys the L-BTC and releases the original coins. This process is managed by a federation of about 15 companies that jointly hold the keys to the network’s reserves. Any significant operation, such as a withdrawal of bitcoins, must be approved by at least 11 of these 15 members.
The stolen funds—3,996 bitcoins, leaving only about 200 bitcoins in the federation’s reserves—passed through the authorization key of SideSwap, an exchange service built on Liquid. The system was designed to function as a whitelist, meaning it should have blocked the transfer of bitcoins to unregistered addresses. However, the flaw lay in the validation logic, which allowed the transaction to proceed despite it being invalid. The issue was a bug in the implementation, which had not yet been resolved at the time of the breach.
In response to the attackers’ message, the Liquid platform chose to engage with them through the same on-chain communication, proposing to contact its security team. The attacker set a condition: the funds would be returned only after the vulnerability is fixed and the patch is deployed across all nodes of Liquid. However, the attacker mentioned returning "most" of the funds, not the full amount, and there is no guarantee that the bitcoins will be returned until they leave his address. In the meantime, Liquid has closed its gateways for converting bitcoins and has halted deposits and withdrawals of L-BTC. While other assets on the platform are unaffected, holders of L-BTC now face a problem: their tokens are supposed to be convertible 1:1 into bitcoins, but the reserves have been significantly reduced. No timeline for recovery or compensation has been provided yet.
Security Breach on Liquid Network Involves Large Bitcoin Loss
AI-rewritten from original reportingHow it works
bitcoinsecurity-breachliquid-networkwhite-hatssidechainpeg-out
Original sources:
- 🇫🇷Numerama
- 🇺🇸TechCrunch
- 🇬🇧TechRadar
- 🇫🇷BFMTV



