
Actors claiming to be white-hat hackers withdrew 4,000 Bitcoin from Liquid's federation wallet, prompting a network pause.
Bitcoin sidechain Liquid paused operations after actors claiming to be white-hat hackers withdrew about 4,000 Bitcoin worth $320 million from its federation wallet.
AI-generated summary
Bitcoin sidechain Liquid operations paused following withdrawal from federation wallet.
Bitcoin sidechain Liquid paused operations after actors claiming to be white-hat hackers withdrew about 4,000 Bitcoin worth $320 million from its federation wallet.
On Sunday, Liquid said that bridge nodes were disabled, preventing new transactions, while exchanges had halted or were preparing to halt L-BTC deposits and withdrawals.
Blockstream, Liquid’s technology provider, started contacting the actors through signed onchain messages. Subsequent messages show the actors told Blockstream to patch the vulnerability and ensure every node was updated before they would return the funds.
They also sent encrypted technical details to Blockstream, according to Galaxy Digital research head Alex Thorn. At the time of writing, the funds had not been returned.
SideSwap said the withdrawal passed through its peg-out service as a customer order using its Peg-out Authorization Key (PAK), but that the key was not compromised. It said the L-BTC used in the transaction originated from a bug in Elements, the open-source software underpinning Liquid, rather than SideSwap’s systems.
Cointelegraph reached out to Liquid Network and Blockstream for comment.
The withdrawn Bitcoin represented roughly 95% of the wallet’s approximately 4,200 BTC balance before the incident. Liquid said other assets issued on the network, including USDT, DePix and real-world assets, were unaffected. The sidechain remained paused while federation members worked to fix the vulnerability.
This is a developing story, and further information will be added as it becomes available.
AI outlook — possibilities, not facts
Liquid network will remain paused until vulnerability is patched and nodes are updated
Very likely · Within days

Liquid Network suspended operations after a software bug in the Elements protocol enabled the unauthorized withdrawal of nearly 4,000 BTC. The funds were moved by self-identified 'whitehats' who have promised to return the Bitcoin once the underlying vulnerability is patched.

Ethereum-compatible layer-1 network Harmony proposed sunsetting its blockchain and migrating its native ONE token to Ethereum via an airdrop, following a recent exploit that created forged tokens.

Approximately 4,000 Bitcoin worth $319 million were drained from the Liquid Network sidechain, with unverified claims of a whitehat hack via an OP_RETURN message. Blockstream paused bridge nodes and advised exchanges to halt LBTC transactions while investigating. Funds moved through SideSwap using a non-compromised Peg-out Authorization Key, with Blockstream citing a bug in Elements software as the cause. Analysts suggest the lack of mixing indicates a whitehat extraction, though security flaws remain under scrutiny.

OpenAI released GPT-6 Astra on September 3, showcasing strong performance in visual understanding, coding, and computer use, including generating 3D models of cities and writing Bach-style music, but receiving criticism for poor writing quality compared to its predecessor, with pricing at $10 per million input and $50 per million output tokens.

Aave DAO voters are deciding whether to delegate limited V4 risk controls on Ethereum and Avalanche to Risk Stewards, allowing approved operators to make constrained changes without full governance votes. The proposal includes no-delay emergency roles that current steward software cannot use, with approval requiring execution by the V4 Security Council. The Risk Steward contracts are undergoing a Certora audit, nearing finalization. Emergency roles would be inert until a future release adds support, but assigning them now would enable faster emergency response later.

Trezor disclosed that a breach at logistics provider ShipMonk exposed contact and order data for approximately 67,000 additional U.S. customers, expanding the initial incident from 13,689 to a total of roughly 80,689 potentially affected individuals. The exposed data includes names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's 90-day data deletion policy and written assurances from ShipMonk. The breach did not compromise Trezor's wallet systems or private keys, but poses risks of phishing, fraud, and physical targeting.