-0.92%
-0.20%
+0.59%
+1.70%
+1.71%
+3.70%
What Happened to the Federation Wallet
Liquid confirmed the withdrawals in a post on X, attributing them to “purported white-hat hackers.” The sidechain is used by more than 80 exchanges and financial institutions for faster Bitcoin settlements, including major names like BTSE and Bitfinex.
Following the incident, Liquid disabled its bridge nodes and asked exchanges to suspend L-BTC deposits and withdrawals while the network works through the aftermath.
The Hackers’ Message
The individuals behind the withdrawal communicated their intentions through an embedded message in a Bitcoin transaction, identifying themselves as “whitehats” and requesting Blockstream’s contact details. Blockstream provided this information on-chain, and communications have since moved to encrypted channels.
The hackers stated they would return most of the Bitcoin once the vulnerability is fixed and Liquid’s nodes are updated. Please fix the bug first,
their message urged. The chain is under risk at latest commit right now.
Alex Thorn, head of research at Galaxy Digital, later confirmed a partial return. He reported the hackers had sent back 3,400 Bitcoin, keeping approximately $47 million worth for themselves.
How the Peg-out Authorization Was Bypassed
Liquid stated the Bitcoin was withdrawn through SideSwap using its Peg-out Authorization Key (PAK). The company maintains that neither SideSwap’s key nor any other PAK was actually compromised, which leaves an open question: how did an apparently authorized SideSwap peg-out empty most of the wallet without a PAK compromise?
Other assets issued on Liquid, including stablecoins, were not directly affected, and the core Bitcoin network remained untouched throughout the incident.
Aneirin Flynn, CEO of FailSafe, suggested preliminary evidence points to a bug that likely allowed the unauthorized minting of L-BTC rather than a stolen key.
A Rough Stretch for Crypto Infrastructure
This breach lands in the middle of a difficult run for digital asset security. A Crypto.com-linked lending platform lost $6 million just last week, and an August hack targeting the Coldcard offline Bitcoin wallet raised similar questions about secure storage.
Ziqing Ang, head of policy in Asia-Pacific at TRM Labs, said these events “may understandably shake consumer confidence” and pointed to the need for stronger safeguards across the full infrastructure stack, not just at the endpoints users interact with directly.
Why Sidechains Carry Different Risk
Liquid operates as a federated sidechain, launched in 2018 with cryptographer Adam Back among its founders at Blockstream. Its federation members collectively manage the Bitcoin backing L-BTC, issuing it against reserves held on the main chain to enable faster settlements than Bitcoin’s base layer allows during periods of congestion.
That federated model is fundamentally different from relying on Bitcoin’s own miners for fund security, and this incident puts that distinction under real scrutiny. Liquid says federation members are actively working to restore normal network activity, though no timeline has been given.
Hashlytics Take
Calling this a “white hat” recovery does a lot of quiet work to soften what actually happened. White hat hackers typically report a vulnerability and wait for a bug bounty. These attackers drained 95% of a federation wallet first, then negotiated terms for giving most of it back, keeping $47 million as an unofficial finder’s fee. Whether that framing holds up depends entirely on whether the remaining funds return and whether Liquid discloses what let a single peg-out authorization drain the wallet almost dry.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



