A group of purported white-hat hackers exploited a vulnerability in the Liquid Network’s transaction-validation software to withdraw approximately $320 million in bitcoin. The attackers drained roughly 4,000 of the 4,200 BTC held on the sidechain by creating unbacked L-BTC tokens and exchanging them for real bitcoin through the network’s peg-out process.

The exploit relied on a flaw in how Liquid cached cryptographic verification results, allowing invalid data to bypass full checks. Following the incident, the actors communicated with Blockstream via Bitcoin’s OP_RETURN field, agreeing to return funds once the bug was fixed. Blockstream deployed updated software, and the hackers returned 3,400 BTC (85% of the total). As of Tuesday, roughly 600 BTC, valued at about $47 million, remained under the actors’ control while discussions continued regarding its return.