Skip to content
event

$320 Million Leaves Liquid Network as White-Hat Label Faces Skepticism

On September 6, 2026, parties claiming to be white-hat researchers withdrew roughly 4,000 BTC worth $320 million from the Liquid Network Federation wallet. Blockstream paused the Bitcoin sidechain and began reaching out to those responsible on-chain, while Ledger's CTO publicly questioned whether the white-hat framing holds.

$320 Million Leaves Liquid Network as White-Hat Label Faces Skepticism
Methodology
Learn more

Original analysis, verified sources, real-world experience

What happened

4,000 BTC left the Liquid Network Federation wallet on September 6, 2026. That is roughly $320 million at the time of the event. According to ForkLog, the Liquid Network team announced the incident publicly, noting that the Blockstream team was working to contact those responsible through an on-chain signed message.

The Block reported that the Bitcoin sidechain was paused immediately, with exchanges suspending LBTC deposits and withdrawals as Blockstream assessed the situation. An OP_RETURN message left on-chain by those who took the funds read "somos white hats. Entre em contato conosco on-chain," according to Cointelegraph BR.

The Liquid Network team itself described the actors as "purported white-hat hackers," a framing that immediately drew criticism. Ledger's Chief Technology Officer questioned the white-hat label applied to the $320 million withdrawal, though he stopped short of calling it theft outright, as noted by BeInCrypto ID and BeInCrypto VI.

How the attack worked

The reported attack vector is an unbacked cross-chain mint – a class of exploit where an attacker generates wrapped or bridged tokens without locking the corresponding collateral on the source chain. In Liquid's case, LBTC is a wrapped representation of Bitcoin that moves across the sidechain. If an attacker can trigger a mint event without depositing the underlying BTC, they end up holding tokens backed by nothing while the protocol registers a liability it cannot cover.

Liquid operates through a Federation model: a group of signatories collectively controls the peg. That setup shifts the security model away from on-chain smart contract logic and toward the integrity of the signatories and the signing infrastructure. A compromise of that signing layer – whether through key theft, signature replay, or a flaw in how the Federation processes mint instructions – can drain the peg wallet without triggering on-chain alarms until the funds are already gone.

We do not yet have a confirmed technical breakdown of exactly which component failed. What the sources confirm is that roughly 4,000 BTC moved out of the Federation wallet, the bridge was paused, and Blockstream is in the process of identifying those responsible. We will update this analysis as Blockstream publishes a post-mortem.

What user funds are at risk

The 4,000 BTC figure represents the confirmed withdrawal reported by ForkLog and Cointelegraph BR. Anyone holding LBTC on exchanges or in wallets at the time of the incident faces uncertainty until Blockstream confirms whether the peg is fully collateralized or partially backed.

Exchanges moved quickly. As The Block confirmed, LBTC deposits and withdrawals were suspended across platforms as a precaution. That freeze protects against further outflows but also means LBTC holders cannot currently redeem their positions.

Whether funds are recoverable depends entirely on the intent of those who took them. If the white-hat claim is genuine, return of the 4,000 BTC is possible. If it is not, recovery odds fall sharply – Bitcoin transactions are irreversible, and the Federation model means there is no on-chain governance mechanism to force a rollback. The Ledger CTO's public skepticism, reported by BeInCrypto TR, reflects how thin the evidence for good-faith intent is at this stage.

Pattern recognition

This event fits a well-documented exploit family: federation or multisig bridge compromise leading to unauthorized minting or direct drain. Three prior cases share the same structural fingerprint.

Ronin Network: Sources covering this Liquid incident explicitly draw the comparison in their reporting. The Ronin bridge, which secured assets for Axie Infinity, relied on a small validator set. Attackers compromised enough validator keys to authorize fraudulent withdrawals. The lesson was the same as here: when security rests on a federation of key holders rather than trustless code, the attack surface is the people and their key management infrastructure.

Wormhole: The Wormhole bridge exploit involved a flaw in how the protocol verified guardian signatures before minting wrapped tokens. The attacker minted wrapped ETH without depositing the underlying collateral – structurally identical to an unbacked cross-chain mint. The mechanism was different but the outcome rhymes: a bridge that believed it had collateral it did not.

BSC Bridge: The BNB Chain bridge suffered an exploit that allowed an attacker to produce fraudulent proof messages that the bridge accepted as valid, again generating tokens without legitimate backing. That incident also triggered a chain pause, the same response Blockstream took here.

The common thread across all three: the moment a bridge trusts a message rather than verifying collateral on both ends atomically, it creates a gap an attacker can step into.

What to do now

  • Do not deposit or withdraw LBTC. Exchanges have already suspended these operations. Any attempt to move LBTC outside of official exchange flows carries the risk of transacting against an undercollateralized asset.
  • Check your exchange's status page. If you hold LBTC on any exchange, confirm whether that exchange has paused LBTC-related operations and monitor their official communications for updates on redeemability.
  • Do not accept LBTC as payment. Until Blockstream confirms the peg is fully intact and the bridge resumes, LBTC's backing is unverified. Receiving it as payment for goods or services exposes you to the full downside if the white-hat claim proves false.
  • Monitor Blockstream's official channels and on-chain messaging. Blockstream stated it is contacting those responsible via signed on-chain message. Any confirmed response from the actors will be visible on-chain before it appears in press coverage.
  • If you hold BTC on Liquid itself (not wrapped elsewhere), contact your custodian directly. Your exposure depends on whether your BTC was inside the Federation wallet or held separately. Do not assume – ask for written confirmation of your specific balance's status.

FAQ

Is Liquid Network operating normally right now?

No. As of the reporting from The Block, the sidechain has been paused and exchanges have suspended LBTC deposits and withdrawals while Blockstream investigates.

Are the people who took the funds actually white-hat hackers?

They left an on-chain message claiming white-hat status, but Ledger's CTO publicly questioned that label without calling it outright theft, according to BeInCrypto ID. No independent verification of the claim exists at the time of writing.

Can the 4,000 BTC be returned?

Blockstream is attempting to reach those responsible via on-chain signed message, as reported by ForkLog. Return is possible if the actors cooperate, but Bitcoin transactions cannot be reversed by the network itself, so recovery depends entirely on their willingness to return the funds.

This article is for educational purposes and is not investment advice. Cryptocurrencies carry high risk. Only trade with funds you can afford to lose.

CoinMagnetic

CoinMagnetic Team

Crypto investors since 2017. We trade with our own money and test every exchange ourselves.

Updated: September 2026

Follow our analysis on Telegram

We publish analysis, digests and forecasts on our Telegram channel.

Follow the channel

Related articles