Blockstream’s Liquid sidechain has been paused after nearly all of the bitcoin held in its federation wallet was withdrawn on Sunday, with the recipient later identifying themselves onchain as white hats.
Liquid said the funds were moved through a working authorization key, not a stolen one. That leaves the route out of the peg unexplained. The wallet backing all L-BTC currently in circulation now holds 197.47 BTC.
Two transfers moved nearly 4,000 BTC
The outflow happened in two transactions. The first was confirmed in block 965780 at 14:01 UTC and sent 2.5 BTC. The second followed 27 minutes later and sent 3,995.99999857 BTC.
Both transfers went to the same Bitcoin address, bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte, which now holds 3,998.49748445 BTC. At CoinGecko’s quoted bitcoin price of $79,901, that stash was worth about $319.5 million. Bitcoin was up 0.10% on the day.
Onchain messages claimed white-hat status
Four hours after the second withdrawal, the destination address consolidated the funds into a single output and attached an OP_RETURN message that read, “we are whitehats. contact us on chain.”
The same transaction also sent 1,000 satoshis back to the federation wallet that had just been drained.
About an hour later, Blockstream responded onchain by paying 1,000 satoshis to that address with the message, “Please contact security@blockstream.com.”
Liquid published its own account of the incident at 4:25 p.m. ET. “Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet,” the network wrote.
It added: “What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others.”
Bridge nodes disabled and L-BTC transfers paused
According to Liquid, bridge nodes were disabled, which means no new transactions can be submitted. The network also told exchanges to pause L-BTC deposits and withdrawals.
Liquid said USDT, DePix, and other assets issued on Liquid were unaffected. It also said Liquid wallets would be impacted and apologized for the inconvenience. The statement did not describe the vulnerability.
Peg wallet uses 11-of-15 multisig and a PAK list
The spending script in the withdrawal transactions shows the peg wallet is an 11-of-15 multisig. Peg-outs face a second restriction through the PAK list.
That means bitcoin can only leave to an address controlled by an authorized user. Liquid’s own documentation says, “it takes three days to update the PAK list. This allows the network to detect an attacker that is able to compromise a set of functionaries before the attacker is able to make a withdrawal to their own wallet.”
The key used in the withdrawals belonged to SideSwap. SideSwap is a federation member that performs peg-outs on behalf of Liquid users.
Peg accounting roughly matches the remaining balance
By the explorer’s peg accounting, L-BTC has recorded 18,356.88 BTC of peg-ins, 18,149.60 BTC of peg-outs, and 10.03 BTC burned. That leaves about 197.25 BTC outstanding against the 197.47 BTC still in the wallet.
The report noted that Liquid transactions are confidential by default, so those totals cannot rule out the possibility that L-BTC was created outside the peg.
A Signal handle then appeared onchain
Two hours after the first message, a third transaction sent 69,093 satoshis to the same address together with the text, “Please contact us on Signal @m671aw.70.”
Samson Mow, chief executive of JAN3 and Blockstream’s former chief strategy officer, said in reply to a thread about the incident that “the request for Signal did not come from the same address.” Onchain data backs that up: the message was sent to the address holding the funds, not from it.
Ledger chief technology officer Charles Guillemet had written earlier in the same thread that the behavior did not match responsible disclosure. “White hats don’t drain a bridge and then solicit an ‘on-chain’ contact,” he wrote, comparing the incident to the Ronin bridge attack.
After the Signal message appeared, Guillemet allowed for another reading. “It doesn’t look like usual white hats practices, but usual criminal orgs don’t usually try to contact their victims either,” he wrote. “There’s hope. This could be people with good intentions that intensively played with recent LLMs and are not used to responsible disclosures.”
Blockstream had proposed a replacement bridge design
As of publication, Blockstream chief executive Adam Back had not commented publicly, and the Liquid account had not posted again after its statement.
Blockstream published a Liquid roadmap in May that included work on a “BitVM-style 1-of-n bridge” designed to reduce trust in the functionary set. That design is not live. Sunday’s withdrawal used the federated peg it was supposed to replace.
Liquid has operated since 2018
Liquid launched in 2018 as a settlement layer for exchanges and traders. It later expanded into a smart-contract chain for bitcoin, most recently with Simplicity.
The report also noted that this is the second bitcoin-adjacent network in two weeks to shut down over a security issue rather than keep operating through it. On Aug. 26, Core Lightning maintainers told node operators to go offline without publishing a patch.

