Liquid Network Bitcoin Sidechain Halted After $320 Million Breach
Security

Liquid Network Bitcoin Sidechain Halted After $320 Million Breach

September 7, 20264 min read

The Bitcoin sidechain Liquid Network halted all transactions overnight on September 7 after $320 million worth of bitcoin was drained from the network. Blockstream, the company behind Liquid, is trying to reach whoever is responsible for the withdrawal while it checks the consortium's code for other flaws.

What Actually Happened to the Liquid Network?

Liquid Network runs as a Bitcoin sidechain, a separate network pegged to the main chain through a 1-to-1 coin swap. Blockstream launched the project in 2018 as a settlement layer for exchanges, where transfers move faster than on the main Bitcoin network and transaction amounts stay hidden from outside observers. Unlike the Bitcoin protocol itself, a sidechain adds an extra layer of trust on top of the base blockchain, and that extra layer is what failed this time. According to CoinDesk, attackers exploited a flaw in how the federated wallet signs transactions and moved the funds to their own addresses within a few hours.

The exact cause of the flaw has not been officially confirmed. Blockstream halted all fund movement on the network as soon as the issue surfaced, and transactions remained frozen at the time of publication. By the size of the withdrawal, the incident ranks among the largest security failures in Bitcoin-adjacent infrastructure in recent years.

Bottom line: The attack hit Liquid's shared federated wallet that holds the network's collateral, not the personal wallets of individual bitcoin holders.

How Is the Attacked Network Structured?

Liquid Network is run by a consortium of several dozen members, including exchanges, miners, and financial firms, who jointly sign transactions through a multisig setup. It is a federated model: no single member of the consortium can move funds on its own, and decisions require reaching a set signature threshold. That threshold exists so that breaching one company alone would not be enough to steal funds, but the attackers bypassed not one company's wallet, but the signature coordination mechanism inside the consortium itself.

The LBTC token on this network mirrors bitcoin at a 1-to-1 ratio, and every LBTC issued is theoretically backed by real BTC held in the consortium's shared vault. That works much like any wrapped token, where trust rests not on Bitcoin's code but on the honesty and security of whoever holds the collateral.

  • Key point: Liquid's features include faster transfers between exchanges, confidential transaction amounts, and issuance of tokenized assets.
  • Only consortium members, which include major exchanges and financial institutions, can operate the network.
  • A regular Bitcoin holder who keeps coins in a personal wallet never directly interacts with this infrastructure.
  • LBTC is mostly used by traders and exchanges for fast settlement with each other, not by retail users.

What Does the Attackers' "White Hat" Claim Mean?

Whoever drained the funds publicly called themselves security researchers and claimed they found the flaw before malicious actors could. A similar pattern has played out before in the crypto industry, for example during the 2021 Poly Network hack, when the attacker eventually returned nearly the entire sum. In cases like this, attackers often withdraw everything first and only later negotiate with the project team over a partial or full return in exchange for anonymity and a reward. Industry bug bounty programs typically offer a reward of 5% to 10% of the recovered amount, though terms vary by project.

There is no formal guarantee of a return. Blockstream has not confirmed any negotiations with whoever is behind the withdrawal and has not given a timeline for restoring the network.

Liquid Network: Key Figures
Amount drained$320M in BTC
Network launch year2018
DeveloperBlockstream
Network statusTransactions halted

Why Are Exchanges and LBTC Holders Feeling It?

After the network halt, centralized exchanges suspended LBTC deposits and withdrawals until Blockstream restores the consortium's operations. The reason for the caution is simple. If the network's collateral is in question, exchanges do not want to credit clients with a token whose backing is temporarily unclear. For traders, this means funds held in LBTC are frozen for now. Converting LBTC back into regular Bitcoin is not possible until the consortium confirms the collateral is untouched.

Holders of Bitcoin outside the Liquid network were not directly affected. LBTC's share of total bitcoin supply is small, so the event had only a moderate effect on the main coin's price, without sharp drops. Most of the market reaction stayed centered on LBTC and the exchanges that handle it.

What Happens Next for the Network

Blockstream says it will publish investigation details once it finishes checking the consortium's code for other vulnerabilities. Restoring the network depends on confirming the security of the federated wallet for every member, not just patching a single hole. Consortium members are likely to review their transaction-signing process and multisig thresholds so a similar attack cannot happen again.

For regular Bitcoin holders, the episode is a reminder: the more intermediate layers built on top of the base blockchain, the more points where something can fail. The Bitcoin network itself was untouched during the incident, which is the key difference between attacks like this one and a breach of the base protocol.

Comments

Your email address will not be published. Required fields are marked *

or verify by email