Security & Audits
Share
A software flaw in Liquid Network enabled the withdrawal of ~4,000 BTC ($320M), with the attacker claiming to be a white-hat hacker.
Millions of dollars worth of Bitcoin have been withdrawn from Liquid Network, a settlement platform used by cryptocurrency exchanges, in the latest major security incident to hit the digital asset industry this year.
The entity behind the withdrawal is reportedly presenting itself as a “white-hat hacker” and has indicated that the funds could be returned once the underlying vulnerability is addressed.
Liquid Network, launched by Blockstream in 2018, said approximately 4,000 BTC out of the 4,200 BTC held in its federation wallet had been removed.
The network is operated by a federation of more than 80 participants, including exchanges, infrastructure providers and asset managers. Following the incident, Liquid suspended new transactions and warned users that its wallets could experience disruptions while members worked to restore normal operations.
The incident is particularly significant because Liquid was designed to address one of Bitcoin’s key limitations for exchanges: relatively slow transaction settlement. The network issues L-BTC against Bitcoin held in reserve, allowing transactions to be settled more quickly. The removal of almost the entire reserve, however, raises serious questions about the security of this model.
Unlike many cryptocurrency breaches, the incident does not appear to have resulted from compromised passwords or private keys.
Instead, the withdrawn funds were moved through SideSwap, an approved trading platform. Blockstream later identified a software vulnerability that had enabled the creation of some of the Bitcoin involved through a system known as Elements.
SideSwap said it could not distinguish between coins generated through the vulnerability and legitimate Bitcoin, meaning both were treated in the same way. Other asset types operating on Liquid were not affected.
A white-hat hacker is an ethical security researcher who exploits vulnerabilities to expose or address weaknesses before malicious actors can take advantage of them. In some cases, such hackers move vulnerable funds to prevent further losses and negotiate their return after the security issue has been fixed.
In the Liquid incident, the hacker is reportedly communicating with network maintainers through on-chain Bitcoin transactions and has promised to return the funds once the vulnerability is patched.
One message urged network operators to fix the software flaw first and ensure that all nodes had been updated before the Bitcoin was transferred back.
Security specialists say the vulnerability appears to exist at the node level within Liquid’s transaction software, rather than involving compromised cryptographic keys or hardware security modules.
That distinction is important because it highlights a broader challenge facing digital asset infrastructure: securing the software that processes and validates transactions can be just as critical as protecting private keys and wallets.
The Liquid incident comes shortly after approximately $6 million was drained from a lending platform linked to Crypto.com, while an earlier breach in August affected the Coldcard hardware wallet.
Liquid has not yet announced when normal network operations will resume or confirmed whether all of the withdrawn Bitcoin will ultimately be returned.
In my view, the Liquid incident highlights how security risks in the crypto industry are becoming increasingly tied to the infrastructure supporting digital assets, rather than simply to wallets and private keys.
A vulnerability at the software or node level can potentially put an entire reserve at risk, even when conventional security measures remain intact. As blockchain-based settlement systems become more important to exchanges and institutional markets, rigorous code audits, node-level monitoring and rapid vulnerability response will become essential. The willingness of the alleged white-hat hacker to return the funds may limit the final damage, but it does not remove the underlying concern: a network designed to make settlement faster must also prove that it can protect the assets underpinning that speed.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks

Why Zondacrypto’s Collapse Would Unfold Differently in the UAE
Walid Abou Zaki
Aug 28, 2026
8 min

The Missing Orchestration Layer Holding Back Institutional Digital Assets
Julian Sawyer
Aug 18, 2026
5 min

Beyond Crypto Access: How ARP Digital Is Building the UAE’s Digital Capital Infrastructure
Anna K.
Aug 17, 2026
8 min
Read More Articles
In the Same Space

ARK Invest, Glassnode Map Decentralization Tradeoffs Across Bitcoin, Ethereum and Solana
News Desk
Sep 3, 2026
5 min

Corporate Crypto Treasury Boom: Strive Enters Top Five Bitcoin Holders as Bitmine Nears 5% of ETH Supply
News Desk
Sep 1, 2026
4 min

Crypto-Backed Lending Spreads to Russia as Sberbank Joins Global Bank Push
News Desk
Aug 31, 2026
6 min

Crypto Funds Pull In $3.2B in One Week, Marking Biggest Inflow Since 2025
News Desk
Aug 31, 2026
3 min