Attack on Liquid Network: hackers withdrew 4,000 BTC, exposing vulnerabilities in Bitcoin sidechains
One of the oldest and most reputable institutional Bitcoin sidechains, Liquid Network from Blockstream, has encountered a large-scale security incident. The attackers managed to initiate an unauthorized withdrawal of approximately 4,000 BTC (about $320 million at the current rate) from the federation’s multisig storage. Network operators were forced to urgently suspend the operation of sidechains and 2-Way Peg bridges, which sparked a wave of debate about the reliability of federated models in Web3.
How did the attackers manage to withdraw 4,000 BTC from the federation-wallet?
According to preliminary data from on-chain researchers, the attack was not related to a fundamental vulnerability in Bitcoin cryptography. The hacking vector occurred at the infrastructure level of federation members (functionaries). The attackers compromised the server access keys of several validating nodes, gaining the necessary quorum of signatures to confirm the transaction to unlock native BTC on the main network. The incident once again confirmed the trend of 2026: the weak link is increasingly becoming the operational security of servers and multi-sig configurations, and not the logic of the underlying protocol.
Why does the white hat hacker status leave security questions open?
A few hours after the withdrawal of funds, the persons controlling the addresses with the stolen bitcoins contacted Blockstream and declared themselves “white hats”, beginning a phased return of the coins. However, as of September 9, about $47 million in cryptocurrency still remains unrecovered. For institutional traders and market makers, the fact that third parties were able to bypass standard procedures to seize control of a third of a billion dollars of storage was a serious blow to the reputation of Liquid’s federated model.
What does this incident mean for the-wrapped-bitcoin (L-BTC) market?
Events around the Liquid Network provoked a local department of the tokenized Bitcoin L-BTC on decentralized sites. Arbitrageurs and liquidity providers began hedging risks en masse by withdrawing funds to native BTC and alternative non-custodial L2 solutions based on BitVM and ZK proofs. Analysts expect stricter requirements for sidechain validators and an accelerated industry transition from trusted multi-sig committees to mathematically provable verification protocols without human intervention.


