The Liquid Network experienced a major security incident on or shortly before September 6, when approximately 4,000 BTC, valued around $320 million USD, was withdrawn from the Liquid Federation wallet by purported white-hat hackers [1, 2, 3]. Liquid Network confirmed the withdrawal occurred via the SideSwap Peg-out Authorization Key (PAK), but stated the key itself was not compromised, nor were any other keys [1].

As a result, the network paused all new transactions and disabled bridge nodes pending investigation [1, 2, 3]. Exchanges relying on Liquid Network, including BTSE and Bitfinex, have suspended deposit and withdrawal functions until the issue is resolved [2].

Other Liquid assets such as USDT, DePix, and real-world assets (RWAs) remained unaffected by the incident [1]. The Liquid Network, founded in 2018 by Blockstream and governed by a federation of more than 80 exchanges and companies, is known for improving Bitcoin settlement speeds by issuing liquid Bitcoin (L-BTC) tokens backed 1:1 by locked BTC [2, 3]. Before the incident, about 4,200 BTC was held in the federation wallet, meaning roughly 95% of the funds were withdrawn in this event [2, 3].

FailSafe CEO Flynn, a cybersecurity expert, suggested the breach may involve a system vulnerability allowing abnormal minting of L-BTC, which could have enabled the unauthorized withdrawal[ s2]. The Liquid Network expressed regret for impacts on wallets and pledged that federation members are actively working to restore normal operations [1].

The purported attackers are described as white-hat hackers who may intend to return the stolen Bitcoins, though this has not been confirmed [1, 2, 3]. The network remains paused as of today, September 7, while the investigation continues and remediation efforts proceed [1, 2, 3].