Liquid Network Suffers $320M Exploit: What Really Happened?
The crypto market is facing another major security incident, and this time the spotlight is on Liquid Network, a Bitcoin-based settlement network used by exchanges and other market participants.
According to reports, approximately 4,000 BTC, worth around $320 million, were withdrawn from Liquid’s federation wallet. The withdrawal represented roughly 95% of the Bitcoin reserves held in the wallet before the incident. Liquid subsequently halted new transactions as a precaution.
Interestingly, the incident does not appear to be a simple case of private keys being stolen. Liquid said the key involved in the withdrawal was not compromised. The funds were moved through SideSwap, an authorized settlement route, while the underlying issue appears to involve the mechanism used to validate peg-outs.
Another unusual part of the story is the attacker’s claim. An on-chain message identified the actors as “white hats”, suggesting they may have exploited the vulnerability to prevent a potentially larger loss. However, that claim has not been independently verified.
The latest development is even more interesting: reports say the attackers have offered to return most of the funds after the vulnerability is fixed. Blockstream has also said its bridge nodes were patched, potentially clearing the way for the funds to be returned.
This incident highlights an important lesson for the crypto industry: strong cryptography alone is not enough. Validation logic, bridges, federation infrastructure and peg-out mechanisms can all become critical attack surfaces.
The big question now is simple: Will the full $320M be returned, and what will this incident mean for confidence in Liquid Network?#USIranTradeTankerStrikesEscalate #ZcashRises45%WeeklyToHighestSince2016 #IMFSaysElSalvadorBTCNoPublicFunds #LiquidNetworkSuffers$320MExploit
The crypto market is facing another major security incident, and this time the spotlight is on Liquid Network, a Bitcoin-based settlement network used by exchanges and other market participants.
According to reports, approximately 4,000 BTC, worth around $320 million, were withdrawn from Liquid’s federation wallet. The withdrawal represented roughly 95% of the Bitcoin reserves held in the wallet before the incident. Liquid subsequently halted new transactions as a precaution.
Interestingly, the incident does not appear to be a simple case of private keys being stolen. Liquid said the key involved in the withdrawal was not compromised. The funds were moved through SideSwap, an authorized settlement route, while the underlying issue appears to involve the mechanism used to validate peg-outs.
Another unusual part of the story is the attacker’s claim. An on-chain message identified the actors as “white hats”, suggesting they may have exploited the vulnerability to prevent a potentially larger loss. However, that claim has not been independently verified.
The latest development is even more interesting: reports say the attackers have offered to return most of the funds after the vulnerability is fixed. Blockstream has also said its bridge nodes were patched, potentially clearing the way for the funds to be returned.
This incident highlights an important lesson for the crypto industry: strong cryptography alone is not enough. Validation logic, bridges, federation infrastructure and peg-out mechanisms can all become critical attack surfaces.
The big question now is simple: Will the full $320M be returned, and what will this incident mean for confidence in Liquid Network?#USIranTradeTankerStrikesEscalate #ZcashRises45%WeeklyToHighestSince2016 #IMFSaysElSalvadorBTCNoPublicFunds #LiquidNetworkSuffers$320MExploit

