White‑Hat Hackers Withdraw $320 Million Bitcoin From Liquid Network, Funds Expected to Return After Patch

TL;DR
- Around $320 M in Bitcoin was moved from Liquid Network in a claimed white‑hat exploit.
- Liquid halted operations while Blockstream patched the bridge nodes.
- Hackers say they will return the funds after the security fix is applied.
Incident Overview
On September 7, 2026, the Liquid Network—Blockstream’s Bitcoin sidechain—experienced a massive unauthorized withdrawal of roughly $320 million worth of Bitcoin. Multiple outlets, including Decrypt and CryptoPotato, reported that the actors described themselves as “white‑hat” hackers, stating they intended to expose a vulnerability and return the assets once a fix was in place. The withdrawal was executed through the network’s bridge nodes, which connect Liquid to the Bitcoin main chain, and the perpetrators communicated their intentions via on‑chain messages.
Immediate Response and Technical Fix
Following the incident, Liquid suspended all activity, including LBTC trading, to contain any further risk. Daily Hodl noted that the exchange halted operations after the withdrawal, emphasizing the “friendly” nature of the attack as claimed by the actors. Blockstream quickly moved to address the breach; as reported by CryptoBriefing, the company confirmed that the compromised bridge nodes had been patched and that user funds were now secure. Blockstream’s statement indicated that the patch eliminates the specific exploit used in the withdrawal, paving the way for the stolen Bitcoin to be returned to their original addresses.
Broader Implications for Sidechain Security
The episode underscores persistent security challenges in sidechain and cross‑chain bridge architectures. CryptoPotato highlighted that the event reveals “significant vulnerabilities” in the Liquid Network’s infrastructure, potentially eroding investor confidence. NewsBTC added that the pause raises concerns about the platform’s liquidity and overall security posture. While the actors’ claim of a white‑hat motive suggests a non‑malicious intent, the scale of the theft—one of the largest ever on a Bitcoin sidechain—demonstrates the systemic risk such bridges can pose if left unchecked.
Stakeholders, including custodians and traders, are now watching closely to see whether the promised fund return materializes and how Blockstream’s remediation measures will be audited. The incident may prompt broader industry scrutiny of bridge designs and encourage more rigorous security audits for sidechain solutions moving forward.
This article was reconstructed from public reporting with AI assistance and is for informational purposes only — not financial advice. See our editorial policy.
Related
Citi and DBS Execute First Weekend Tokenized USD Transfer via SWIFT Ledger
Coinbase Seeks Regulatory Approval for U.S. Single-Stock Perpetual FuturesRobinhood Chain Records Surge in DEX Activity as Binance Expands TradFi Offerings
Payward Group Expands Strategic Initiatives Through London Stock Exchange Partnership