
Liquid Network has paused its Bitcoin sidechain after nearly 4,000 BTC worth about $320 million left the federation wallet through a SideSwap peg-out, reducing the reserve from roughly 4,200 BTC to about 200 BTC.
The security incident unfolded on September 6 and removed roughly 95% of the Bitcoin backing L-BTC. Bridge nodes were subsequently disabled, preventing new transactions from entering Liquid, while exchanges were instructed to suspend L-BTC deposits and withdrawals.
The withdrawal passed through SideSwap’s Peg-out Authorization Key, or PAK, which is authorized to request Bitcoin redemptions from Liquid’s federation.
A customer sent roughly 4,000 L-BTC through SideSwap’s peg-out service shortly after 14:05 UTC. The federation then released approximately 3,996 BTC on Bitcoin at 14:28 UTC.
The SideSwap authorization key was not compromised, nor has Liquid identified a compromise of the federation’s other signing keys. The L-BTC presented for redemption instead originated from an apparent bug in Elements, the open-source software underlying Liquid.
That distinction makes the incident materially different from a stolen bridge key or multisig takeover. The peg-out followed an authorized path, but the L-BTC entering that process should not have existed with corresponding Bitcoin backing.
A technical analysis of the exact Elements vulnerability has not yet been published.
The withdrawn funds were consolidated into a Bitcoin address holding roughly 3,998 BTC. An onchain transaction included the message: “we are whitehats. contact us on chain.”
Blockstream responded through Bitcoin with contact information for its security team as efforts began to establish communication with the address controllers.
The white-hat characterization remains unverified. Ledger CTO Charles Guillemet questioned the approach, arguing that draining nearly an entire bridge reserve before seeking contact falls outside conventional responsible-disclosure practices. The Bitcoin remained concentrated in the identified address early September 7 rather than moving through exchanges, mixers or cross-chain services.
Recent attackers have taken very different paths after obtaining Bitcoin. Funds from the Coldcard Wave 3 attack began moving through THORChain last week, converting BTC into ETH as investigators tracked the new destination addresses.
Liquid represents BTC locked on Bitcoin as L-BTC on its sidechain, with federation members operating the infrastructure securing peg-ins and peg-outs. USDT, DePix and other assets issued on Liquid were not directly affected by the unauthorized L-BTC creation, although the network pause prevents normal transaction processing.
The episode also differs from conventional bridge drains such as the $24.15 million AFX Trade exploit, where validator signatures authorized an unauthorized USDC withdrawal from bridge reserves.
Liquid bridge nodes remained disabled early September 7, exchanges were keeping L-BTC deposits and withdrawals suspended, and roughly 3,998 BTC remained at the Bitcoin address connected to the withdrawal.
The post Liquid Network Pauses After $320M Bitcoin Peg-Out Drains Most Reserves appeared first on Crypto Adventure.