A group of purported white-hat hackers exploited a vulnerability in the Liquid Network’s transaction-validation software to withdraw approximately $320 million in bitcoin. The attackers drained roughly 4,000 of the 4,200 BTC held on the sidechain by creating unbacked L-BTC tokens and exchanging them for real bitcoin through the network’s peg-out process.
The exploit relied on a flaw in how Liquid cached cryptographic verification results, allowing invalid data to bypass full checks. Following the incident, the actors communicated with Blockstream via Bitcoin’s OP_RETURN field, agreeing to return funds once the bug was fixed. Blockstream deployed updated software, and the hackers returned 3,400 BTC (85% of the total). As of Tuesday, roughly 600 BTC, valued at about $47 million, remained under the actors’ control while discussions continued regarding its return.
This incident highlights the operational risks inherent in layer-two infrastructure, demonstrating that vulnerabilities in sidechain validation logic can compromise underlying assets even when the base blockchain remains secure. The exploitation of caching mechanisms underscores the complexity of maintaining integrity in systems designed for confidentiality and speed, where cryptographic proofs are essential for preventing the creation of unbacked synthetic assets.
From an institutional adoption perspective, the partial recovery of funds offers a nuanced case study in crisis management. While the return of 85% of the stolen value mitigates immediate financial loss, the retention of $47 million by unidentified actors introduces uncertainty regarding final settlement and potential bounty arrangements. This event serves as a critical reminder for market participants that security assessments must extend beyond core protocols to include the specific implementation details of bridges, custodial layers, and auxiliary networks.


