Crypto

Blockstream in Tense On-Chain Negotiations After $320M Liquid Sidechain Exploit

Exploiter Holds 3,998.5 BTC Hostage, Demands Full Node Update

A high-stakes on-chain negotiation is underway between blockchain development firm Blockstream and an unidentified exploiter who drained approximately 4,000 Bitcoin (BTC)—worth roughly $320 million—from the Liquid sidechain network. The incident, which occurred on Sunday, has reignited intense debate within the cryptocurrency security community over the boundaries of “white hat” hacking. The attacker, who successfully siphoned off roughly 95% of the Bitcoin held in Liquid’s main federation wallet, has offered to return the bulk of the funds, but only after Blockstream deploys a permanent patch and updates all nodes across the network.

Prior to the withdrawal, the Liquid federation wallet held approximately 4,200 BTC. It now holds just 200 BTC, meaning nearly 95% of the collateral backing the sidechain’s L-BTC has been cleared out. While other digital assets hosted on the Liquid network—including Tether (USDT), DePix, and various tokenized real-world assets—remain unaffected, Blockstream took the immediate precaution of disabling all Liquid bridge nodes on Sunday to prevent further withdrawals. The underlying Bitcoin main network remains entirely secure and unaffected by the vulnerability.

According to transaction logs, the exploit did not involve a direct compromise of the federation’s private cryptographic keys. Instead, the attacker capitalized on a logical flaw within Elements—the open-source, sidechain-capable codebase developed by Blockstream that powers Liquid. By exploiting the bug, the attacker was able to mint unbacked L-BTC out of thin air. The exploit has highlighted a critical operational bottleneck for federated protocols: patch lag. Though Blockstream has not publicly detailed the exact nature of the software bug, GitHub repository data reveals that a fix addressing the vulnerability had actually been merged into the Elements codebase five weeks prior to the attack. However, because the patch had not yet been fully deployed or mandated across all active federation nodes, the live network remained exposed.

With these newly minted tokens in hand, the attacker initiated what appeared to be a standard transaction through SideSwap, a decentralized exchange and federation member that provides “peg-out” services—the mechanism used to convert L-BTC back into native Bitcoin on the main blockchain. SideSwap reported that a customer transferred 4,000 L-BTC to its platform. Operating under valid automated protocols, SideSwap burned the sidechain tokens and authorized the federation wallet to release the underlying Bitcoin. Exactly 23 minutes later, the Liquid federation wallet disbursed 3,996 BTC to the user’s mainnet address.

Following the drain, the exploiter left an embedded message within a Bitcoin transaction reading: *”we are whitehats. contact us on chain.”* Blockstream executives responded roughly one hour later, providing a secure email address. Since then, the two parties have been communicating publicly using PGP-signed cryptographic messages embedded directly inside Bitcoin transactions. A timeline of the communications published by Samson Mow, the former Chief Security Officer of Blockstream, indicates that the exploiter’s address currently holds approximately 3,998.5 BTC.

Myriad: Bitcoin next price move? Click to make your prediction.

While the attacker has agreed in principle to return the majority of the capital, they have conditioned the refund on a full network upgrade. The exploiter noted that the sidechain remains highly vulnerable at its latest code commit, demanding that every node operator apply the software fix before the funds are sent back. Blockstream quickly accepted the terms in a confirmed transaction block, replying: *”Yes, thank you.”* Liquid, a federated sidechain designed by Blockstream to facilitate faster and more private transactions, operates by locking native Bitcoin in a multisignature wallet controlled by a decentralized group of consensus members known as the Liquid Federation. In return, the network mints an equivalent amount of Liquid Bitcoin (L-BTC) on a 1:1 basis.

The situation has drawn sharp criticism from prominent cybersecurity figures who question whether the attacker’s actions can genuinely be classified as ethical white-hat hacking. Charles Guillemet, Chief Technology Officer at hardware wallet manufacturer Ledger, compared the incident to past high-profile decentralized finance exploits, such as the $620 million Ronin Network bridge hack and the $197 million Euler Finance exploit. Guillemet expressed skepticism over the attacker’s methods, arguing that true security researchers do not drain hundreds of millions of dollars from live production environments to force a negotiation. Guillemet noted that the definition of ethical hacking in the cryptocurrency space has undergone a troubling shift. He observed that some actors now routinely seize entire protocol reserves, holding the assets hostage until developers comply with their conditions, rather than identifying the vulnerability privately through coordinated disclosure programs.

The incident underscores the persistent vulnerability of cross-chain and sidechain bridges, which have collectively lost billions of dollars to exploits over the last several years. Unlike decentralized smart-contract bridges on platforms like Ethereum, which rely on code-based locked pools, Liquid’s federated bridge relies on a consortium of trusted nodes to sign off on peg-ins and peg-outs. While this architecture was designed to mitigate the risks associated with complex smart contracts, the Elements bug demonstrates that logical flaws in the underlying node software can still bypass federation security checks entirely. Blockstream has not yet announced a timeline for when the node software updates will be fully implemented or when the Liquid bridge nodes will resume normal operations.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *