Liquid Network said on Sept. 6 that purported white-hat hackers withdrew approximately 4,000 BTC, valued at about $320 million, from its federation wallet. After the withdrawal, the network halted bridge activity, while Blockstream began contacting the parties on-chain, according to Liquid Network.
Liquid’s description of the actors as purported white hats has not been independently established in the information released so far. Bridge nodes were disabled, and exchanges either suspended or prepared to suspend L-BTC deposits and withdrawals, effectively stopping new activity on the network, The Block reported.
4,000 BTC withdrawal triggers bridge and exchange halt
Liquid characterized the actors as purported white hats, though that description has not been independently established in the information released so far. Its immediate response was to disable the network’s bridge infrastructure, while exchange suspensions restricted L-BTC deposits and withdrawals.
The on-chain outreach by Blockstream means the parties behind the withdrawal have been contacted through Bitcoin transaction data or associated messaging. Liquid did not provide further details in the supplied statement on the status of those contacts or whether the Bitcoin had been returned.
Withdrawal accounted for roughly 95% of reported reserves
The 4,000 BTC withdrawal represented roughly 95% of Liquid's reported Bitcoin reserves. The reserve balance stood at approximately 4,200 BTC before the incident, making the amount removed a near-total drawdown of the reported holdings.
At the stated value of about $320 million, the implied figure was roughly $80,000 per BTC. The reported reserve comparison underscores why bridge operations and L-BTC transfers were halted immediately after the withdrawal.
SideSwap points to an Elements software bug
SideSwap said its peg-out authorization key was not compromised, according to CoinDesk.
The company indicated that the incident stemmed from a bug in Elements, the open-source software underlying Liquid.
That explanation points away from a compromise of the peg-out authorization key as the reported failure point. SideSwap’s statement does not, on its own, establish a final technical diagnosis of the withdrawal.