Blockstream Liquid Sidechain Paused Following $320 Million Unauthorized Peg-out
A software bug allowed the creation of unbacked L-BTC, leading to a massive withdrawal that the perpetrators claim was a white-hat action.
Quick Look
- Blockstream's Liquid sidechain is paused after 4,000 BTC ($320M) were withdrawn via a software bug.
- The perpetrators, claiming to be white-hat hackers, are currently negotiating the return of funds with Blockstream while demanding a patch for the underlying vulnerability.
AI-generated summary
Why It Matters
The Liquid sidechain uses a federation of members to manage peg-outs. The incident involved a bug in the Elements software that allowed the creation of unbacked L-BTC.
Blockstream's Liquid sidechain has been paused since Sunday, after about 4,000 BTC worth roughly $320 million left the federation wallet that backs every L-BTC in circulation.
SideSwap, a federation member running a peg-out service, said a customer sent it 4,000 L-BTC at 14:05 UTC. It burned them under a valid authorization, and 23 minutes later the federation paid out 3,996 BTC.
Liquid said the funds moved through SideSwap's Peg-out Authorization Key, but that neither that key nor any other federation key was compromised. SideSwap said none of its systems were breached either, and pointed to a bug in Elements, the software Liquid runs on.
Blockstream has not explained the bug, though a fix for it was added to Liquid's underlying software five weeks earlier. Nothing was forced out of the wallet: someone created L-BTC that no Bitcoin was backing, then cashed it in through a peg-out that looked ordinary.
The wallet held around 4,200 BTC before Sunday and roughly 200 after.
Talking to the supposed white hats
The party left an on-chain message reading "we are whitehats. contact us on chain." Blockstream answered an hour later with an email address, and the two have traded PGP-signed messages inside Bitcoin transactions since.
The hackers offered to send most of the coins back, then attached a condition: patch the bug first, because the chain is still at risk at the latest commit, and update every node. Blockstream's reply, "Yes, thank you," answered the earlier offer, and was confirmed in the same block as the condition.
Ledger chief technology officer Charles Guillemet initially argued that "White hats don't drain a bridge and then solicit an "on-chain" contact," likening it to the Ronin and Euler hacks. He briefly allowed they might be people who "intensively played with recent LLMs," then hardened once the condition appeared: white hat practice has "changed," he wrote, adding that, "Now they steal the money and refuse to give back the funds before the vulnerability is fixed..."
Former Blockstream security chief Samson Mow, who published a timeline of the exchange, puts the hackers' address at about 3,998.5 BTC.
Other assets on Liquid, including USDT, DePix and tokenized real-world assets, were untouched, and Bitcoin's own network is unaffected.
What to Watch
AI outlook — possibilities, not facts
Blockstream will release a patch for the Elements software.
Very likely · Within days
Open Questions
- Will the hackers return the funds?
- What is the specific nature of the Elements bug?







